a number of previously-existing bugs in several TLS middlebox products. (意訳) 今回のことでいくつかのTLSミドルボックス製品に以前から存在していた複数の不具合が明らかになった。 原因は、TLS レコードの2バイトの長さフィールドを読み切るループを書いていないこと 「Most buggy servers are not prepared to have to call read() more than once」— tldr.fail 実名で記録されている製品 Vercel 2023-08 修正 ZScaler 2023-09 修正 Palo Alto 2025-03 修正 (PAN-247099) Fortinet IPS Engine 更新 (#1097642) Apache Traffic Server 2025-06 修正 Envoy not planned でクローズ Broadcom ProxySG 2024年後半 修正 Ingress Nginx 未修正・リポジトリはアーカイブ Cloudflare「この互換性問題がなければ、Chrome の PQ 鍵交換の展開は5年早かっただろう」(訳) 結論 → もともとあったバグを、PQC が踏んだだけ 出典: "Advancing Our Amazing Bet on Asymmetric Cryptography" Chromium Blog 2024-05-23 https://blog.google/chromium/advancing-our-amazing-bet-onasymmetric/ / tldr.fail https://tldr.fail/ / "State of the post-quantum Internet in 2025" https://blog.cloudflare.com/pq-2025/ 7
限り、CRQC を持つ攻撃者は、 現行証明書を偽造するだけで接続を破れる CRQC = いまの公開鍵暗号を現実的な時間で解ける規模の量子計算機 配ることと、現行証明書の受け入れをやめることは、 別の工程。 IAB も同じことを言っている Post-quantum authentication is the harder half, and 赤い部分は、すべて守れていない。 緑になるのは、クライアントが PQ を必須にしてから。 it lags. 鍵交換ではなく認証のほう、つまり署名と証明書のワ ークショップが、この2週間後にプラハで開かれる。 図の出典: David Benjamin "How to beat the S-curve: Post-Quantum Authentication" p.15、IETF 126 SAAG(2026-07-24) / IAB pqws Call for Papers 18
いま通信を録っておいて、量子計算機が 接続しているその場で証明書を偽造し、 できてから復号する。 通信に割り込む。 録るだけなので、攻撃者は今この瞬間に 偽造には、その瞬間に量子計算機が要る。 何も持っていなくてよい。 過去に遡って破ることはできない。 できる前に手を打たないと間に合わない。 できるまでに間に合えばよい。 NIST IR 8547(ドラフト) Encrypted data remains at risk because of the "harvest now, decrypt later" threat in which adversaries collect encrypted data now with the goal of decrypting it once quantum technology matures. IETF 126 SAAG / David Benjamin Actual goal is a security property: an active quantum adversary cannot intercept connections between updated clients and updated services. この差が、本編の「どこも鍵交換を先に済ませている」の理由。急ぐ理由が、そもそも違う。 出典: NIST IR 8547 ipd / David Benjamin "How to beat the S-curve" p.7・p.11、IETF 126 SAAG 21
付録 G 2025-10-28 https://blog.cloudflare.com/pq-2025/ Cloudflare Keeping the Internet fast and secure: introducing Merkle Tree Certificates 2025-10-28 https://blog.cloudflare.com/bootstrap-mtc/ Cloudflare Automatic Key Exchange for origins 2026-09-08 https://blog.cloudflare.com/automatic-key-exchange-for-origins/ ISRG A Post-Quantum Future for Let's Encrypt 2026-06-03 https://letsencrypt.org/2026/06/03/pq-certs Chromium Advancing Our Amazing Bet on Asymmetric Cryptography 2024-05-23 https://blog.google/chromium/advancing-our-amazing-bet-on-asymmetric/ D. Adrian ほか tldr.fail — ClientHello が分割されると壊れる実装の一覧 随時更新 https://tldr.fail/ Dubey & Varshney Measurement Study of Post-Quantum Readiness of Internet: 2026 2026-06-15 https://arxiv.org/abs/2606.16473 Mozilla Bug 1967998 — SMTP sending fails with Office 365 on Thunderbird 138-142 — https://bugzilla.mozilla.org/show_bug.cgi?id=1967998 28