• Latest
  • Trending
  • All
Answer card: Classic McEliece is now in ISO/IEC 18033-2, the first post-quantum algorithm to reach full ISO standardization, built on a 1978 cryptosystem, with a public key that can exceed one megabyte.

Classic McEliece is the first ISO post-quantum standard

18 July 2026
Answer card stating that Qwen-Image-2.1, released on 20 September 2026, ships open weights with a 7 billion parameter diffusion transformer, a Qwen3-VL 8B text encoder and an RGBA VAE totalling about 33 gigabytes in BF16, under the Qwen Research License that limits use to research or evaluation and requires a separate commercial licence, unlike the Apache 2.0 licence of Qwen-Image 1.0.

Qwen-Image-2.1 brings the weights back, but not the Apache licence

21 September 2026
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
Answer card stating that Qwen3.8-Omni-Flash launched on 17 September 2026 as an API only model on Alibaba Cloud Model Studio, taking text, images, audio and video in a 1M token context and returning text only, priced at 0.15 dollars per million input tokens for every modality and 0.47 dollars per million output tokens in the international regions, with no open weights published and the Qwen-Live Harness GitHub repository returning 404.

Qwen3.8-Omni-Flash bills audio at $0.15 and ships no weights

18 September 2026
Answer card stating that on 15 September 2026 AWS said it is unable to restore access to resources and data hosted exclusively in the Middle East Bahrain region me-south-1 and in the mec1-az2 zone of the UAE region, because the damage spanned multiple Availability Zones and exceeded what multi-AZ services are designed to withstand.

AWS can’t restore me-south-1, six months after the drone strikes

17 September 2026
Answer card stating that Google released Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking on 15 September 2026 at 3 dollars per million audio input tokens and 12 dollars out, that the thinking model requires asynchronous tools, and that Artificial Analysis scores it 82.6 on its Speech to Speech Quality Index.

Gemini 3.8 Live Extended Thinking rejects any tool that blocks

16 September 2026
Answer card summarising the Atria Dawn Preview release: 744B GLM-5.2 base, MIT licence, 1.5 TB BF16 and 756 GB FP8 checkpoints, 256K context, top on five of sixteen benchmark rows and trailing on SWE-bench Pro.

Atria Dawn Preview is 744B under MIT, and the BF16 weighs 1.5 TB

15 September 2026
Answer card stating that OpenAI released the Agents API in public beta on 10 September 2026 with no separate fee, billed through model tokens, tool calls and hosted sandbox time, with a choice of OpenAI hosted, self hosted or partner sandboxes, US only data residency and no Zero Data Retention support.

OpenAI’s Agents API has no fee, no ZDR and a one hour sandbox clock

14 September 2026
Answer card: Sakana Fugu Max at $2 and $6 per million tokens, Fugu Ultra v2 unchanged at $5 and $30, and Sakana saying Ultra v2 scores without Fable 5 or GPT-6 Astra in its pool.

Fugu Max costs $2 and $6 while Fugu Ultra v2 runs without Fable 5

13 September 2026
Answer card stating that DeepSeek released DeepSeek-V4.1-Flash on 10 September 2026 as a 552 billion parameter mixture of experts model with a new causal encoder decoder architecture that activates 8 billion parameters on input and 16 billion on output, with native vision, a one million token context and MIT licensed weights, that the API model name is now deepseek-flash at 0.15 dollars per million input tokens and 0.60 dollars per million output tokens off peak, and that DeepSeek announced V4 Pro would be routed to V4.1-Flash from 14 September and reversed that on 11 September.

DeepSeek V4.1-Flash arrived, and the V4 Pro retirement lasted a day

12 September 2026
Answer card stating that Cognition released SWE-2 on 10 September 2026, a coding model post-trained from Kimi K3, scoring 50.0 percent on FrontierCode 1.1 Main against 50.9 percent for Claude Fable 5.1 and 27.3 percent on Terminal-Bench 4 against 55.8 percent, available only inside Devin.

SWE-2 trails Fable 5.1 by one point, and by 28 on Terminal-Bench 4

11 September 2026
Answer card for Meta Muse, free to 100 million tokens a week then $20 a month, launched 8 September 2026 for United States adults only, running in a dedicated per user virtual machine.

Does Meta Muse do enough to earn your inbox and a card on file?

9 September 2026
  • About
  • Contact
  • Privacy
  • Legal
Tuesday, September 22, 2026
  • Login
Packet Nebula
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About
No Result
View All Result
Packet Nebula
No Result
View All Result
Home Security

Classic McEliece is the first ISO post-quantum standard

by stephane
18 July 2026
in Security
0
Answer card: Classic McEliece is now in ISO/IEC 18033-2, the first post-quantum algorithm to reach full ISO standardization, built on a 1978 cryptosystem, with a public key that can exceed one megabyte.
492
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

So a 1978 cryptosystem just quietly became an international standard, and most of us missed it. On July 15, UK firm Post-Quantum announced that Classic McEliece is now part of ISO/IEC 18033-2, making it the first post-quantum algorithm to clear full ISO standardization. That's the headline, and it's real. Here's the part the press release skips over: this doesn't make McEliece your new TLS default. NIST already picked something else for that (ML-KEM), and McEliece hauls around a public key that can run past a megabyte. We've been tracking the post-quantum shift for a while, and this one is genuinely interesting, just not for the reason the announcement implies. It's a standard built for a specific job, not a drop-in for everything.

The short answer

On July 15, Post-Quantum announced Classic McEliece is now part of ISO/IEC 18033-2, the first post-quantum algorithm to clear full ISO standardization. It’s a real milestone. It is not, however, your new TLS default: NIST already picked ML-KEM for that, and McEliece carries a public key that can pass a megabyte. Think long-lived, static keys, not handshakes.

ISO/IEC 18033-2first PQC algorithm to get there
~1 MBMcEliece public key (ML-KEM: ~1 KB)
1978the cryptosystem it builds on
Answer card: Classic McEliece is now in ISO/IEC 18033-2, the first post-quantum algorithm to reach full ISO standardization, built on a 1978 cryptosystem, with a public key that can exceed one megabyte.
The one-card version. A big milestone for a very old algorithm, with a very specific job.

What actually got standardized

Here’s the plain version. ISO/IEC 18033-2 is the international standard for asymmetric ciphers, and it now includes Classic McEliece. The UK firm Post-Quantum, which drove the algorithm’s design alongside a group of cryptographers, announced it on July 15. They’re right to call it a first: no post-quantum algorithm had reached ISO standardization before this.

Classic McEliece is a KEM, a key-encapsulation mechanism. It’s the machinery two parties use to agree on a shared secret so they can then encrypt traffic with something fast. What makes it unusual is its age. The core idea comes from a 1978 paper by Robert McEliece, and in close to fifty years nobody has found a practical break, quantum or classical. That track record is the entire pitch. Germany’s BSI and the Dutch NCSC have both recommended it for exactly that reason: it’s boring, and boring is what you want in cryptography.

One thing to keep straight, because the coverage kept blurring it. ISO is not NIST. This standardization sits next to, not on top of, NIST’s own post-quantum work. NIST already chose a different KEM as its primary answer, and that choice still stands.

The catch is the key size

This is the honest catch, and it’s a large one. McEliece is secure. It’s also enormous where it hurts.

Comparison chart on a log scale of public key sizes in bytes: ML-KEM-768 at 1,184, mceliece348864 at 261,120, and mceliece6688128 at 1,044,992. Classic McEliece public keys are roughly a thousand times larger than ML-KEM.
Public key bytes, log scale. McEliece keys run about a thousand times bigger than ML-KEM's.

NIST’s own read on McEliece is a two-liner: smallest ciphertexts, largest public keys. Both halves matter. The smallest McEliece parameter set, mceliece348864, has a public key of 261,120 bytes, roughly 255 KB. Step up to mceliece6688128 and it’s 1,044,992 bytes, over a megabyte. Compare that to ML-KEM-768, NIST’s standard for general use, whose public key is 1,184 bytes. That’s about a thousand-fold difference.

The flip side is real too. McEliece ciphertexts are tiny, on the order of a couple hundred bytes, while ML-KEM-768 sends 1,088 bytes per ciphertext. So the shape of the tradeoff is clear once you see it. McEliece is brutal on the key you publish and gentle on every message after. That’s a terrible profile for a TLS handshake, where the server ships its key on every connection, and a fine one when the key gets installed once and sits there for years.

So who is this actually for

Not your web server. For TLS and everyday key exchange, the answer is still ML-KEM, which NIST standardized as FIPS 203 and which your browser probably negotiated already today without telling you. If you want the signature side of this same story, we wrote up why ML-DSA is the post-quantum signature to ship.

Where McEliece earns its place is the long game. The threat everyone’s actually planning around is “harvest now, decrypt later”: an adversary records your encrypted traffic today and cracks it once a quantum computer exists. For data with a long shelf life (medical records, intellectual property, state secrets), the confidentiality has to survive decades, and a conservative algorithm nobody has dented since 1978 is an easy thing to justify to a risk committee. That’s the pitch for quantum-safe VPNs, stored data, and identity systems built to outlive the hardware they run on.

Post-Quantum also leaned on a concrete demo to answer the “keys are too big” objection. Working with the Czech defense manufacturer STV Group, they showed Classic McEliece running on drones in communication-denied environments, edge hardware where you’d assume a megabyte key would be a non-starter. It ran. That doesn’t make a 1 MB key free, but it does puncture the idea that it’s automatically impractical.

What this means for you

Checklist: what the ISO standardization of Classic McEliece changes. Real: first PQC algorithm in ISO, conservative security since 1978, recommended by BSI and the Dutch NCSC, tiny ciphertexts, proven on edge hardware. Not so fast: it is not a NIST FIPS standard, ML-KEM is still the TLS answer, public keys pass 1 MB, tooling is thin next to ML-KEM.
What actually changed, and what didn't. An ISO stamp is not a deployment plan.

Probably nothing you touch this week. If you run web services, keep letting ML-KEM do its job and treat this as good background news, not a to-do. If you work anywhere data has to stay secret for ten or twenty years, or you build for constrained, long-lived systems, this is worth a real look, because now there’s an international standard behind it and a couple of national agencies pointing the same way.

The one trap to avoid is reading “first ISO post-quantum standard” as “the winner.” It isn’t a ranking. It’s one more tool getting a spec, aimed at a narrow, important slice of the problem. If you want to sanity-check what your own endpoints negotiate today, our SSL Certificate Checker reads back the chain and expiry, and the TLS 1.2 versus TLS 1.3 breakdown covers the handshake all of this eventually has to fit inside.

The honest read

An ISO stamp on a 1978 algorithm is a genuinely nice milestone, and it’s also easy to oversell. McEliece isn’t replacing ML-KEM, and the megabyte public key is a real constraint that a single drone demo doesn’t erase. What the standard does is give the people who need paranoid, long-horizon confidentiality a recognized way to deploy the most conservative option on the board. That’s a smaller story than the headline, and a more useful one. Watch whether TLS-facing libraries and hardware vendors actually pick it up for those niche cases. That’s the signal that this graduates from press release to something you’d deploy.

Sources: Post-Quantum’s announcement via Quantum Computing Report and The Quantum Insider (both July 15, 2026); public key and ciphertext sizes from the Classic McEliece parameter sets; ML-KEM sizes and NIST’s status from FIPS 203 and NIST’s fourth-round report. The BSI and Dutch NCSC recommendations and the STV Group drone demonstration are as reported by Post-Quantum.

Frequently asked questions

What is Classic McEliece?

Classic McEliece is a code-based key-encapsulation mechanism (KEM), a way to agree on a shared secret over an insecure channel. It builds directly on a cryptosystem Robert McEliece published in 1978, which has resisted attack for close to fifty years, including from quantum algorithms. It uses error-correcting codes rather than the lattice math behind ML-KEM. Its defining trait is a very large public key paired with a very small ciphertext.

What does the ISO/IEC 18033-2 standardization actually mean?

It means Classic McEliece now has an internationally recognized specification for how it should be implemented, which helps different vendors interoperate and gives risk-averse buyers (governments, defense, healthcare) a standard to point to. It was standardized under ISO/IEC 18033-2, the standard for asymmetric ciphers, in 2026, and announced on July 15, 2026. It is the first post-quantum algorithm to reach that milestone. ISO standardization is separate from NIST standardization, so this does not override NIST FIPS 203.

Should I switch my TLS certificates or key exchange to Classic McEliece?

Almost certainly not. For TLS and most everyday key exchange, NIST already standardized ML-KEM as FIPS 203, and modern browsers and servers negotiate it already. McEliece public keys are enormous (from about 255 KB up past 1 MB), which is a poor fit for a handshake that ships the key every time. McEliece makes more sense where a public key is distributed once and lives a long time.

Why does Classic McEliece have such large keys?

The security comes from the difficulty of decoding a random-looking linear code, and the public key is essentially a big matrix describing that code. That matrix is what makes the key large: the smallest parameter set, mceliece348864, has a 261,120-byte public key, and mceliece6688128 is 1,044,992 bytes. The upside is that the ciphertext stays tiny, on the order of a couple hundred bytes, which is smaller than ML-KEM.

Is Classic McEliece a NIST-approved standard too?

Not as a primary standard. NIST selected ML-KEM (from CRYSTALS-Kyber) as its main post-quantum KEM in FIPS 203. Classic McEliece was carried into the NIST fourth round as a candidate that NIST rates highly on security but flags for its large public keys. So as of now it is an ISO standard, not a NIST FIPS one, and the two decisions were made by different bodies for different reasons.

Tags: cryptographyisokemnewspost-quantumquantum
Share197Tweet123
stephane

stephane

  • Trending
  • Comments
  • Latest
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
The Agentic Coding section of the official Hy4 preview benchmark appendix published by Tencent, a table comparing Hy3 and Hy4 preview against DeepSeek V4 Pro 0813, Qwen 3.8 Max, GLM 5.3, Kimi K3, GPT 5.6 Sol and Claude Opus 5 across SWE-bench Multilingual, SWE-bench Pro, DeepSWE, three SWE Atlas tasks, SWE-Marathon, Terminal-Bench 2.1, NL2Repo-Bench, CyberGym, ProgramBench, PostTrainBench and Harbor-Index.

Tencent’s 770B Hy4 tops one benchmark row in 46

3 September 2026
Answer card: Qwen 3.7 Max is API-only and cannot run locally yet; the open Qwen models (Qwen 3.6 27B, qwen3:8b to 32b) run offline via Ollama.

Qwen 3.7 local: what you can actually run offline

22 June 2026
Answer card: JWTs are not encrypted, anyone can read them; the signature proves who issued the token, not who may read it.

Are JWTs encrypted? No, and the difference will bite you

0
Answer card: a random 8 character password falls in under 2 hours offline, while 16 random characters hold for 1.4 trillion years at the same speed.

How long does it take to crack a password in 2026?

0
Answer card: three DNS records decide if your mail lands or bounces; SPF lists allowed senders, DKIM signs messages, DMARC sets the failure policy.

SPF, DKIM and DMARC explained: the records your email needs

0
Answer card stating that Qwen-Image-2.1, released on 20 September 2026, ships open weights with a 7 billion parameter diffusion transformer, a Qwen3-VL 8B text encoder and an RGBA VAE totalling about 33 gigabytes in BF16, under the Qwen Research License that limits use to research or evaluation and requires a separate commercial licence, unlike the Apache 2.0 licence of Qwen-Image 1.0.

Qwen-Image-2.1 brings the weights back, but not the Apache licence

21 September 2026
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
  • About
  • Contact
  • Privacy
  • Legal

Copyright © 2026 Stephane Cardon.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About

Copyright © 2026 Stephane Cardon.