Quantum-safecryptography, learned in the open.
A free course, interactive tools and a news desk for the move to post-quantum cryptography.
Background: a 2D lattice and its closest-vector search, the geometry behind ML-KEM.
The standards are final. What is left is the migration, and the migration needs people who understand it.
NIST published FIPS 203, 204 and 205 in August 2024. Since then the work has moved to engineers, architects and auditors who have to change real systems. PQCrypt is our contribution to that ecosystem: everything we learn, written down, sourced, and free to use.
What we build
Every number shows its receipts.
All 152 numbers in the course live in one keyed file. Each carries a tag: measured by a command we ran, sourced from a primary document, derived with the arithmetic shown, or estimated with assumptions listed. Hover any badge to see where it came from.
When we find an error, the old value stays visible. Our early research notes claimed a 12.5 KB post-quantum certificate chain. Measuring it gave a different answer.
- ML-KEM-768 public keyFIPS 203, Table 3
- 1184 BSOURCED
- Hybrid ClientHelloopenssl s_client
- 1484 BMEASURED
- ML-DSA-65 chain vs RSA-2048 chain22,945 / 3,739
- 6.14×DERIVED
- DER overhead per certificateassumptions listed
- 393 BESTIMATED
Correction on record
12.5 KB13.8 KB22,945 BMEASURED
Three-certificate ML-DSA-65 chain, PEM, measured. The 13.8 KB figure turned out to include an RSA leaf.
Tools that show the arithmetic.
Flagship tool
TLS handshake byte calculator
Pick a key exchange, signature algorithm and chain shape. Get per-message bytes, segment count, the initcwnd warning and added latency, with every step shown.
Open calculatorSignature sizes
Mosca calculator
x + y > z
Shelf life plus migration time against the quantum timeline, with presets for bank data classes.
Regulatory timeline
Dated, sourced deadlines by jurisdiction, with a countdown to the next binding one.
Algorithm decision tree
From use case to recommendation, with the reasoning path and caveats visible.
What moved this month
All newsHow a lesson ships
PQCrypt is built with Claude Code. Lessons are written and checked through four agent roles, each with its own brief and its own rules.
Research
Find two to four primary sources for the topic. Standards, papers and regulator texts first.
Verify
Re-check every number and status claim against its source, with a verification date.
Run
Execute each lab and record the real output. A lab is never written to confirm a target number.
Challenge
A hostile review as a bank crypto architect and as a lost beginner. Findings are fixed or answered.
Start at module zero.
Set up OpenSSL 3.5 or newer, confirm ML-KEM and ML-DSA work on your machine, and work forward from there.
Start learning