Same algorithms, different rulebooks

The world has agreed on the maths of post-quantum cryptography. It has not agreed on how to use it — and the traffic on the wire has already changed shape. Four developments from the past fortnight, and what they mean for New Zealand.

There is a comfortable version of the post-quantum story in which the US standards body NIST finished the job in August 2024, and everything since has been implementation detail. Four items published in the last two weeks make that hard to sustain.

A Chinese research group has measured what post-quantum web traffic actually looks like, and found that security tools trained on the old traffic stop working on the new. The cryptography firm PQShield has shown that the United States and Europe have taken directly opposing positions on a basic design question. France has taken over coordination of a G7 working group on migration. And a payments-infrastructure founder has argued in public that financial systems built today on old cryptography are obsolete on arrival.

Together they describe a transition that is fragmenting rather than converging. New Zealand is not in any of the rooms where that fragmentation is being managed.

Post-quantum traffic looks different, and tools notice

Researchers from Beihang University and two Chinese partner institutions published The Colossus with Feet of Clay on 24 August. They first measured 2,060 of the world’s most-visited websites and found that just over half — 50.3% — now use post-quantum key exchange when you connect to them. Another 38.6% still use the classical method, and roughly one in ten is stuck on the older TLS 1.2, which cannot support post-quantum at all.

The interesting part is what that change does to the shape of the traffic. Post-quantum key exchange sends far more data during the initial handshake — kilobytes instead of a few dozen bytes. That extra material spills across network packet boundaries, so the pattern of packet sizes and timings looks noticeably different, even though nothing about the website itself has changed.

The researchers tested five machine-learning tools that identify which website someone visited purely from those traffic patterns. Two findings matter for practitioners.

Post-quantum encryption does not hide you. Retrain the tools on post-quantum traffic and they work just as well as before. Any privacy benefit is temporary.

But tools trained on the old traffic fall over badly on the new. The best-performing model went from identifying websites essentially perfectly to getting it right roughly a third of the time. Others collapsed further. Accuracy degraded steadily as the proportion of post-quantum traffic rose — and not always predictably.

The study has real limits: a controlled lab setup, one browser, one vantage point, and it changes only the key-exchange step rather than the digital certificates, which will shift things again. But the underlying mechanism is straightforward and hard to argue with.

The rulebooks diverge

PQShield published a regional comparison on 3 September that puts a table around something practitioners have been navigating informally for a year.

The sharpest split is over “hybrid” cryptography — running a post-quantum algorithm alongside a traditional one, so that security holds if either survives. America’s National Security Agency prohibits hybrid outright for national security systems and insists on a direct jump to pure post-quantum, using only the largest parameter sizes. France’s ANSSI and Germany’s BSI, the two agencies’ European equivalents, require or strongly recommend the opposite. Britain’s NCSC sits in between, treating hybrid as a reasonable interim step towards pure post-quantum later.

The permitted algorithm lists differ too. A product certified for the German market and one certified for US national security use are, on this question, incompatible.

One thing is converging, though: the deadlines. PQShield notes broad agreement on 2030 for critical products and 2035 as the backstop for everything else.

Coordination, for those in the room

On the same day, Quantum Zeitgeist reported that France’s 2026 G7 presidency has ANSSI chairing the G7 Cybersecurity Working Group, which has issued a statement of practical recommendations on migration. It builds on work Canada started in 2025, and involves European Union institutions alongside national agencies.

On its own this is modest — recommendations, not rules. It matters as a signal of structure: the countries that already have binding positions are now coordinating them with each other, under European chairmanship.

The finance case, read carefully

The Quantum Insider carried a guest post on 2 September by Ryan Kirkley, who runs a settlement-network company, arguing that payment infrastructure built today on classical cryptography is born obsolete.

Treat the framing with appropriate scepticism — he is selling the alternative, and several of his supporting claims about quantum hardware timelines are second-hand and worth verifying before repeating. The structural argument holds up better. Settlement systems are built to run for thirty to fifty years, which is exactly the retention profile that makes “harvest now, decrypt later” — recording encrypted traffic today to decrypt once the hardware exists — a practical concern rather than a theoretical one.

There is an instructive contradiction in it. Kirkley’s recommended architecture is hybrid. That is the European position, and it is prohibited for US national security systems. Two competent parties, same standards, opposite conclusions.

The NZ read

Our headline number is close to global; the composition is not. Our June re-scan of 118 NZ critical infrastructure entities found 52.2% supporting post-quantum, against 50.3% in the Beihang sample. Different methods and different populations, so the comparison is rough — and the more important difference is beneath the number. Much of New Zealand’s figure is delivered by content delivery networks rather than by the organisations themselves. Only 25 of 115 origin servers do it natively.

The traffic finding lands on defenders, not just attackers. The Beihang paper is framed around eavesdropping, but the mechanism is indifferent to who is watching. Any tool that learned normal traffic patterns before 2025 — network monitoring, anomaly baselines, deep packet inspection — is now looking at a shifted picture. In New Zealand, where post-quantum arrived for many entities as a CDN default rather than a deliberate decision, that shift happened without a change ticket. Worth asking when those baselines were last re-established.

We have no position on the hybrid question. New Zealand remains alone among the Five Eyes without a formal migration deadline, and the NZISM says nothing on hybrid versus pure. That gap has consequences now: anyone buying a security appliance in 2026 is inheriting someone else’s regulatory position by default, usually the vendor’s home country. The Critical Infrastructure Bill is expected later this year; the consultation it follows made no substantive mention of cryptography, which is what we submitted on in April.

The banking argument arrives here via Sydney. Four of our big five banks are Australian subsidiaries, so these decisions are made offshore. Our scans keep finding only ANZ running post-quantum at its own servers among the big four.

The timelines are being set in rooms we are not in. But inventory work — knowing what cryptography you actually run, and where — takes the same time regardless of which rulebook eventually applies, and it is the one thing that can start before the rulebook is written.


Kaysec is the post-quantum security practice of Spinsphere, a New Zealand-based quantum technology company. We help NZ organisations with cryptographic inventory, harvest-now-decrypt-later risk assessment, TLS configuration auditing, and PQC migration planning. Get in touch.

If it lives long, protect it.


References

  • Li, B., et al. (2026). The Colossus with Feet of Clay: Debunking Encrypted Traffic Classifiers under PQC Evolution. arXiv:2608.22683v1, 24 August 2026. https://arxiv.org/pdf/2608.22683v1
  • Stubbs, M. (2026). Regional regulations for cryptography algorithm selection. PQShield, 3 September 2026. https://pqshield.com/regional-regulations-for-cryptography-algorithm-selection/
  • Delaney, I. (2026). ANSSI leads G7 push for quantum-resistant encryption. Quantum Zeitgeist, 3 September 2026. https://quantumzeitgeist.com/quantum-resistant-encryption-anssi-leads-push/
  • Kirkley, R. (2026). Guest Post: Why Financial Infrastructure Needs Post-Quantum Security. The Quantum Insider, 2 September 2026. https://thequantuminsider.com/2026/09/02/financial-systems-quantum-risks/
  • Kaysec (2026). Seven Weeks Later: NZ Critical Infrastructure PQC — The June 2026 Update, 3 June 2026. https://kaysec.spinsphere.xyz/seven-weeks-later-nz-critical-infrastructure-pqc-the-june-2026-update/