• Latest
  • Trending
  • All
Answer card: NIST has nine newer post-quantum signatures in progress, but Cloudflare says deploy ML-DSA now because it is the only standardized and ready option, at the cost of a signature growing from 64 bytes to 2,420.

Ship ML-DSA now, says Cloudflare, and here is what it costs

3 September 2026
Answer card stating that Qwen-Image-2.1, released on 20 September 2026, ships open weights with a 7 billion parameter diffusion transformer, a Qwen3-VL 8B text encoder and an RGBA VAE totalling about 33 gigabytes in BF16, under the Qwen Research License that limits use to research or evaluation and requires a separate commercial licence, unlike the Apache 2.0 licence of Qwen-Image 1.0.

Qwen-Image-2.1 brings the weights back, but not the Apache licence

21 September 2026
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
Answer card stating that Qwen3.8-Omni-Flash launched on 17 September 2026 as an API only model on Alibaba Cloud Model Studio, taking text, images, audio and video in a 1M token context and returning text only, priced at 0.15 dollars per million input tokens for every modality and 0.47 dollars per million output tokens in the international regions, with no open weights published and the Qwen-Live Harness GitHub repository returning 404.

Qwen3.8-Omni-Flash bills audio at $0.15 and ships no weights

18 September 2026
Answer card stating that on 15 September 2026 AWS said it is unable to restore access to resources and data hosted exclusively in the Middle East Bahrain region me-south-1 and in the mec1-az2 zone of the UAE region, because the damage spanned multiple Availability Zones and exceeded what multi-AZ services are designed to withstand.

AWS can’t restore me-south-1, six months after the drone strikes

17 September 2026
Answer card stating that Google released Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking on 15 September 2026 at 3 dollars per million audio input tokens and 12 dollars out, that the thinking model requires asynchronous tools, and that Artificial Analysis scores it 82.6 on its Speech to Speech Quality Index.

Gemini 3.8 Live Extended Thinking rejects any tool that blocks

16 September 2026
Answer card summarising the Atria Dawn Preview release: 744B GLM-5.2 base, MIT licence, 1.5 TB BF16 and 756 GB FP8 checkpoints, 256K context, top on five of sixteen benchmark rows and trailing on SWE-bench Pro.

Atria Dawn Preview is 744B under MIT, and the BF16 weighs 1.5 TB

15 September 2026
Answer card stating that OpenAI released the Agents API in public beta on 10 September 2026 with no separate fee, billed through model tokens, tool calls and hosted sandbox time, with a choice of OpenAI hosted, self hosted or partner sandboxes, US only data residency and no Zero Data Retention support.

OpenAI’s Agents API has no fee, no ZDR and a one hour sandbox clock

14 September 2026
Answer card: Sakana Fugu Max at $2 and $6 per million tokens, Fugu Ultra v2 unchanged at $5 and $30, and Sakana saying Ultra v2 scores without Fable 5 or GPT-6 Astra in its pool.

Fugu Max costs $2 and $6 while Fugu Ultra v2 runs without Fable 5

13 September 2026
Answer card stating that DeepSeek released DeepSeek-V4.1-Flash on 10 September 2026 as a 552 billion parameter mixture of experts model with a new causal encoder decoder architecture that activates 8 billion parameters on input and 16 billion on output, with native vision, a one million token context and MIT licensed weights, that the API model name is now deepseek-flash at 0.15 dollars per million input tokens and 0.60 dollars per million output tokens off peak, and that DeepSeek announced V4 Pro would be routed to V4.1-Flash from 14 September and reversed that on 11 September.

DeepSeek V4.1-Flash arrived, and the V4 Pro retirement lasted a day

12 September 2026
Answer card stating that Cognition released SWE-2 on 10 September 2026, a coding model post-trained from Kimi K3, scoring 50.0 percent on FrontierCode 1.1 Main against 50.9 percent for Claude Fable 5.1 and 27.3 percent on Terminal-Bench 4 against 55.8 percent, available only inside Devin.

SWE-2 trails Fable 5.1 by one point, and by 28 on Terminal-Bench 4

11 September 2026
Answer card for Meta Muse, free to 100 million tokens a week then $20 a month, launched 8 September 2026 for United States adults only, running in a dedicated per user virtual machine.

Does Meta Muse do enough to earn your inbox and a card on file?

9 September 2026
  • About
  • Contact
  • Privacy
  • Legal
Monday, September 21, 2026
  • Login
Packet Nebula
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About
No Result
View All Result
Packet Nebula
No Result
View All Result
Home Security

Ship ML-DSA now, says Cloudflare, and here is what it costs

by stephane
3 September 2026
in Security
0
Answer card: NIST has nine newer post-quantum signatures in progress, but Cloudflare says deploy ML-DSA now because it is the only standardized and ready option, at the cost of a signature growing from 64 bytes to 2,420.
491
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

Picture a quantum computer big enough to forge the signature on google.com's certificate. It doesn't exist yet. When it does, every RSA and elliptic-curve cert on the web turns into a bad photocopy anyone can fake. The fix the industry keeps landing on is ML-DSA, the lattice signature NIST standardized as FIPS 204 back in 2024, and on July 9 Cloudflare wrote the bluntest version of the argument: stop waiting for a prettier algorithm and ship this one. We've watched the post-quantum encryption side get quietly solved already. Signatures are the half that's still dragging, and they're the half that has to be in place before the quantum computer shows up, not after. Here's what ML-DSA actually costs you, in bytes and in verify time, and why the smaller options everyone keeps pointing at won't save you in time.

The short answer

A big enough quantum computer would forge today’s RSA and elliptic-curve certificates. The industry’s answer for signatures is ML-DSA, standardized as FIPS 204. On July 9 Cloudflare made the case to deploy it now rather than wait for the smaller schemes NIST is still building. The price is size, not security. You aren’t migrating this week, but it’s worth knowing where you sign things.

FIPS 204ML-DSA is standardized
2,420 Bsignature (Ed25519: 64 B)
~2033when smaller options arrive
Answer card: NIST has nine newer post-quantum signatures in progress, but Cloudflare says ship ML-DSA now because it is the only standardized and ready option, at the cost of a signature growing from 64 bytes to 2,420.
The one-card version. ML-DSA is the signature you can actually ship, and the cost shows up as bytes.

What ML-DSA is, and why it’s the default

Short version. ML-DSA is a post-quantum signature algorithm NIST published as FIPS 204 in August 2024. You may know it by its competition name, Dilithium. It’s lattice-based, so the math that lets a quantum computer chew through RSA and elliptic-curve keys doesn’t apply to it. That’s the whole point: a signature that still means something after “Q-day”, the hypothetical morning a quantum machine can forge classical certificates.

Here’s the part people miss. Post-quantum encryption is mostly a solved problem already. If you opened a connection to a modern site today, there’s a good chance the key exchange used ML-KEM under the hood and you never noticed. Signatures are the other half, and they’ve lagged. Cloudflare’s July 9 post put it plainly: signatures are the harder migration, and they have to land before the threat is real, not after, because you can’t retroactively re-sign the world’s certificates once a quantum computer is forging them.

The cost is size, not security

This is the honest catch, and it’s a big one. ML-DSA is safe. It’s also fat.

Comparison chart on a log scale of signature sizes in bytes: Ed25519 classical at 64, FN-DSA-512 not ready at 666, ML-DSA-44 at 2,420, and ML-DSA-65 at 3,293. Note that public keys also grow and FN-DSA is not expected before around 2033.
Signature bytes, log scale. ML-DSA is roughly 38 times larger than Ed25519, and the smaller post-quantum option isn't ready.

An Ed25519 signature is 64 bytes. ML-DSA-44, the smallest ML-DSA parameter set, is 2,420 bytes, with a public key of 1,312 bytes against Ed25519’s 32. Step up to ML-DSA-65 and you’re at 3,293 bytes. That balloons the moment you put it in a real TLS handshake, because a certificate carries a signature, and a chain carries several, plus certificate-transparency proofs on top. Independent figures for a depth-two chain with ML-DSA-65 put the on-wire certificate overhead around 17,500 bytes, versus a few hundred today. Every handshake pays that, every time.

Bytes aren’t the only tax. Verification is where your servers and clients spend time, and it’s a touch slower than the fastest classical curves. Not a wall, but not free either. For a busy edge, small per-handshake costs add up across billions of connections, which is exactly why a company like Cloudflare cares about the difference between a 666-byte signature and a 2,420-byte one.

Then why not wait for the small one?

Because “the small one” is a 2033 problem, maybe later. NIST kicked off a second round for signatures precisely because ML-DSA is chunky, and there are nine candidates in play. FN-DSA (Falcon) gives you a 666-byte signature, which is gorgeous by comparison. SQIsign is tiny, 148 bytes. The multivariate schemes go smaller still on the signature while paying it back in monstrous public keys.

The problem isn’t the math. It’s the calendar. Cloudflare’s read is that FN-DSA won’t be standardized before roughly 2033, and the multivariate options push into 2034 and beyond. Their own deployment target for post-quantum signatures is 2029. Do the subtraction: if you wait for the pretty algorithm, you miss your own deadline, and migrations of this size take years to roll through every browser and CA, plus a long tail of embedded devices you forgot you own. So the argument is almost boring in its logic. Ship the one that’s standardized, eat the extra bytes, and swap later if something better actually ships. I think that’s right, honestly, even if it stings to deploy the fat option knowing a leaner one is theoretically coming.

What this means for you

Probably nothing you touch this week.

Checklist: post-quantum encryption with ML-KEM is mostly already on, signatures are the lagging half and ML-DSA is the ready answer, inventory where you sign things now; but handshakes get bigger and slightly slower, browser and CA support is still rolling out, and waiting for FN-DSA or SQIsign risks missing the deadline.
You are not flipping a switch today. The useful move now is knowing where you depend on signatures.

There’s no ML-DSA button to press on your cert renewal yet, and browser plus CA support for these certificates is still landing. What you can do is cheap: map where you actually rely on signatures. TLS certificates, obviously. But also code signing, the firmware on your boxes, any token your systems take on trust. That’s the surface that has to move eventually, and knowing its shape now beats discovering it under deadline. If you want to sanity-check what your endpoints serve today, our SSL Certificate Checker reads back the chain and expiry, and if you’re still fuzzy on where TLS versions sit, the TLS 1.2 versus TLS 1.3 breakdown covers the handshake this all rides on.

The honest read

ML-DSA winning isn’t a story about the best algorithm. It’s a story about the only one that’s ready, and a clock that doesn’t care about elegance. The signatures are big, verification costs a little more, and a leaner scheme is sitting in a NIST queue looking better on paper. None of that changes the call, because a signature you can deploy in 2029 beats a smaller one you can’t touch until 2033. Watch for CA and browser support to firm up over the next year or two. That’s the signal that this stops being a whitepaper argument and starts being a renewal option you’ll actually pick.

Sources: Cloudflare’s post on why we cannot wait for better post-quantum signatures (July 9, 2026), and NIST’s official standard FIPS 204 (ML-DSA), published August 2024. Signature and key sizes are from the FIPS 204 parameter sets; the 2033 and 2029 timelines are Cloudflare’s stated estimates and targets, not fixed dates.

Frequently asked questions

What is ML-DSA?

ML-DSA is a post-quantum digital signature algorithm, standardized by NIST as FIPS 204 in August 2024. It was known during the competition as Dilithium. It is lattice-based, which means a quantum computer cannot break it the way one would break RSA or elliptic-curve signatures. It is meant to sign things like TLS certificates and firmware so that authenticity survives the arrival of quantum computers.

Why does Cloudflare say to ship ML-DSA now instead of waiting?

Because the alternatives are years away. NIST is still working on nine newer signature schemes, some with much smaller signatures, but the fast-following ones like FN-DSA are not expected to be standardized until around 2033, and multivariate schemes even later. Cloudflare argues that migration takes years by itself and that waiting for a smaller algorithm risks missing the window before quantum attacks become real. ML-DSA is the only option standardized and deployable today.

How much bigger is an ML-DSA signature than an elliptic-curve one?

A lot. An Ed25519 signature is 64 bytes with a 32-byte public key. ML-DSA-44 is a 2,420-byte signature with a 1,312-byte public key, and ML-DSA-65 is 3,293 bytes with a 1,952-byte key. In a real TLS handshake with a certificate chain, that pushes the on-wire certificate data from a few hundred bytes into the tens of kilobytes.

Do I need to migrate my certificates to ML-DSA today?

No. There is no switch to flip yet, and browser plus certificate-authority support for ML-DSA certificates is still rolling out. What you can do now is inventory where you rely on signatures (TLS certs, code signing, firmware, tokens) so you know the surface area, and treat post-quantum signatures as a planned migration rather than a surprise. The post-quantum encryption side, using ML-KEM, is already largely on by default.

Is ML-DSA the same thing as post-quantum encryption?

No, and mixing them up is common. Encryption (key exchange) protects the confidentiality of your traffic, and the post-quantum piece there is ML-KEM, which most modern browsers and servers already negotiate. ML-DSA is a signature scheme, which protects authenticity, proving a certificate or a message really came from who it claims. They are separate problems on separate timelines, and signatures are the one still catching up.

Tags: certificatescryptographyml-dsanewspost-quantumtls
Share196Tweet123
stephane

stephane

  • Trending
  • Comments
  • Latest
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
The Agentic Coding section of the official Hy4 preview benchmark appendix published by Tencent, a table comparing Hy3 and Hy4 preview against DeepSeek V4 Pro 0813, Qwen 3.8 Max, GLM 5.3, Kimi K3, GPT 5.6 Sol and Claude Opus 5 across SWE-bench Multilingual, SWE-bench Pro, DeepSWE, three SWE Atlas tasks, SWE-Marathon, Terminal-Bench 2.1, NL2Repo-Bench, CyberGym, ProgramBench, PostTrainBench and Harbor-Index.

Tencent’s 770B Hy4 tops one benchmark row in 46

3 September 2026
Answer card: Qwen 3.7 Max is API-only and cannot run locally yet; the open Qwen models (Qwen 3.6 27B, qwen3:8b to 32b) run offline via Ollama.

Qwen 3.7 local: what you can actually run offline

22 June 2026
Answer card: JWTs are not encrypted, anyone can read them; the signature proves who issued the token, not who may read it.

Are JWTs encrypted? No, and the difference will bite you

0
Answer card: a random 8 character password falls in under 2 hours offline, while 16 random characters hold for 1.4 trillion years at the same speed.

How long does it take to crack a password in 2026?

0
Answer card: three DNS records decide if your mail lands or bounces; SPF lists allowed senders, DKIM signs messages, DMARC sets the failure policy.

SPF, DKIM and DMARC explained: the records your email needs

0
Answer card stating that Qwen-Image-2.1, released on 20 September 2026, ships open weights with a 7 billion parameter diffusion transformer, a Qwen3-VL 8B text encoder and an RGBA VAE totalling about 33 gigabytes in BF16, under the Qwen Research License that limits use to research or evaluation and requires a separate commercial licence, unlike the Apache 2.0 licence of Qwen-Image 1.0.

Qwen-Image-2.1 brings the weights back, but not the Apache licence

21 September 2026
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
  • About
  • Contact
  • Privacy
  • Legal

Copyright © 2026 Stephane Cardon.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About

Copyright © 2026 Stephane Cardon.