Post-Quantum Deployment: Insights from Google, Cloudflare, and Formal Methods | RWPQC 2026, S6
As Post-Quantum Cryptography moves into active production, the world’s largest tech infrastructure providers are uncovering hidden complexities in the transition. Session 6 of RWPQC 2026 explores Google’s emergency planning, Cloudflare’s real-world traffic statistics, and the use of formal methods to ensure the new "iron bridges" of PQC don't collapse. In this session: -Sophie Schmieg (Google): Breaks down the "Long Tail" of migration and the concept of "Yak Shaving:" where rolling out PQC requires fixing unrelated legacy bugs in Windows Direct Access and TPM specifications. She also outlines emergency scenarios, including "Quantum Zero Days." -Bas Westerbaan (Cloudflare): Shares exclusive data showing that 65% of non-bot traffic already uses ML-KEM, while origin servers lag at 10%. He introduces "Merkle Tree Certificates" (MTC) as a way to shrink PQC certificates and prevent protocol ossification. -Francois Dupressoir (University of Bristol): Uses the analogy of bridge engineering to explain why we need "Formal Methods" (machine-checked proofs) to manage the risk of change. He reveals a significant discrepancy found in the XMSS specification through formal verification. Watch to understand HNDL (Harvest Now, Decrypt Later) urgency, the transition from "Standalone" to "Performance" Merkle certificates, and why "Provable Security" is only as good as the machine-checked implementation. Chapters: 00:00 - Introduction to Session 6 01:12 - Sophie Schmieg (Google): The 4 Areas of Crypto Migration 05:31 - Update: Google’s internal and consumer-facing PQC rollout 09:32 - The "Yak Shaving" of Corporate TLS: Windows, TPMs, and RSA-PSS 14:43 - Why Signature Migration is a Key Management Nightmare 16:48 - Emergency Planning: Quantum Zero-Days vs. Timeline Slips 25:17 - Merkle Tree Certificates (MTC) and Certificate Transparency 28:18 - Bas Westerbaan (Cloudflare): Key Agreement on the Public Web 29:30 - Data: 65% of traffic is already Quantum-Safe (ML-KEM 768) 31:32 - The "Configuration Trap": How modernizing can accidentally disable PQC 33:10 - The 2027 Roadmap for Merkle Tree Certificates 38:30 - Solving the Downgrade Problem: HSTS for PQC 45:02 - Choosing the Right Algorithm: Why ML-DSA 44 is the "Safe Bet" 53:10 - Francois Dupressoir: Formal Methods to Manage the Risk of Change 56:49 - The Bridge Analogy: Moving from Stone to Iron (PQC) 01:00:00 - Case Study: Finding a spec error in XMSS (RFC disagreement) 01:03:15 - Building a Chain of Proof: From Design to Optimized Implementation 01:13:11 - Lightweight Verification: Memory Safety and Constant-Time Guarantees #sandboxaq