WSIS Forum 2026
AI-generated report

Post‑Quantum: Preparing the DNS for Post-Quantum Cryptography

14 speakers
Summary

This session focused on the challenges of preparing internet infrastructure - particularly DNS and routing security - for the era of post-quantum cryptography (PQC).

Pierre Bonis, CEO of AFNIC, explained that DNS relies heavily on cryptography through DNSSEC, and that current cryptographic algorithms will not withstand quantum computing . He warned that post-quantum algorithms, while more secure, are larger and slower, potentially creating significant latency and performance issues for DNS resolution . In an extreme scenario, he raised the controversial possibility that DNSSEC could be removed if no viable PQC solution is found, though he acknowledged this would be a deeply undesirable outcome . He also noted a lack of empirical evidence demonstrating the concrete security benefits of DNSSEC deployment, calling for better statistics .

Wout de Natris, coordinator of IS3C, framed the issue as fundamentally a political and economic challenge rather than a purely technical one, stressing that decision-makers must be convinced to act before a quantum breakthrough renders current encryption obsolete . He highlighted the risk of a "digital security and quantum security divide," warning that fragmented, contradictory national regulations - as seen with IoT policies across 21 jurisdictions producing 442 often-contradictory best practices - could prevent coherent global adoption of PQC standards .

Moritz Müller, from SIDN (the .nl registry), provided a technical assessment, noting that DNSSEC is further along in PQC transition planning than RPKI, though neither is ready . He observed that algorithm transitions in DNSSEC have historically taken a decade or more, and that suitable PQC algorithms for DNSSEC are still being standardised . For RPKI, he noted there is less community momentum and no prior experience of algorithm migration .

Participants raised concerns about geopolitical fragmentation leading to incompatible national standards , the need for ICANN to engage more urgently with PQC , and the risk that poor regulation could undermine interoperability . The session concluded with a broad call for cross-stakeholder collaboration, urgency, and coordinated global action to avoid the fragmentation of internet security standards .

Keypoints
  • Overall Purpose

  • The discussion aims to raise awareness about the urgent need to prepare internet infrastructure - particularly DNS-related protocols such as DNSSEC and RPKI - for the transition to post-quantum cryptography (PQC). Organised by AFNIC and the IS3C Dynamic Coalition, the session brings together technical experts, policymakers, and internet governance stakeholders to assess the current state of PQC readiness, identify gaps, and encourage coordinated global action.
  • --
  • Major Discussion Points

  • The threat that quantum computing poses to current cryptographic standards, especially DNSSEC: Current cryptographic algorithms used in DNS security will not withstand quantum computing attacks. Pierre Bonis explained that post-quantum algorithms, while stronger, are larger and slower, potentially creating significant latency and performance issues for DNS resolution. He provocatively raised the "nuclear option" of removing DNSSEC entirely if no viable PQC solution is found, whilst acknowledging this would be deeply undesirable. - The uneven state of PQC readiness between DNSSEC and RPKI: Moritz Müller-Brus noted that DNSSEC is further along in its PQC transition than RPKI, benefiting from prior algorithm migrations and growing community engagement at the IETF. RPKI presents a less clear picture - it is a newer deployment, has never undergone an algorithm change, and lacks the same level of urgency or community focus. He suggested that identifying RPKI's specific transition requirements should be a priority next step. - The lack of urgency and the risk of a "wait-and-see" culture: Wout de Natris stressed that standards deployment has a poor track record globally, and that most stakeholders are waiting for others to act rather than taking initiative. He warned that a powerful enough quantum computer could break all current encryption simultaneously, and that the window for preparation - whilst still open - is narrowing rapidly. He also highlighted that IS3C lacks the structural funding needed to drive awareness and training at the necessary scale. - The risk of fragmentation - both technical and geopolitical: Jacques Beglinger raised the concern that geopolitical competition could lead to incompatible national or regional PQC standards. Peter Koch reinforced this, warning that unwise regulation driven by urgency could result in algorithms being banned or deprecated in some jurisdictions but not others, breaking cross-border DNS interoperability. Wout de Natris responded that proactive community-led testing and implementation of PQC solutions may help prevent poorly designed regulation. - The need for evidence-based justification of DNSSEC and coordinated global policy: Pierre Bonis highlighted a significant gap in empirical data demonstrating the real-world security benefits of DNSSEC, noting he had never seen comparative studies of attack rates in signed versus unsigned zones. Jimson Olufuye echoed this, suggesting ICANN should be asked to provide such statistics. Wout de Natris further argued that PQC policy must be coordinated globally - not siloed by country - pointing to a previous finding of 442 contradictory best practices across just 21 jurisdictions as a cautionary example. ---
  • Overall Tone

  • The discussion opens with an informative and measured tone, as speakers set the technical and organisational context for PQC challenges. It then shifts to a more urgent and cautionary register, particularly when Wout de Natris uses a thought experiment about all digital locks opening simultaneously to convey the stakes of quantum vulnerability. By the latter half of the session, the tone becomes notably more concerned and candid, with speakers openly acknowledging institutional inertia, funding shortfalls, and the danger of fragmentation. Overall, the discussion is constructive and collaborative, ending with a call to action for broader stakeholder engagement rather than despair.
Speakers Overview
PB
Pierre Bonis
111 wpm · 14 min
MM
Moritz Müller-Brus
152 wpm · 8 min
WD
Wout de Natris
143 wpm · 12 min
AM
Audience Member 1
40 wpm · 1 s
AM
Audience Member 2
122 wpm · 10 s
AM
Audience Member 3
78 wpm · 15 s
AM
Audience Member 4
90 wpm · 7 s
JO
Jimson Olufuye
123 wpm · 1 min
S1
Speaker 1
131 wpm · 1 min
PF
Philippe Foucart
121 wpm · 56 s
JB
Jacques Beglinger
86 wpm · 1 min
PK
Peter Koch
139 wpm · 1 min
M
Moderator
136 wpm · 37 s
LC
Lucien Castex
87 wpm · 3 min

Expanded Summary: Preparing the Internet for Post-Quantum Cryptography

#

Session Overview and Context

This session, organised by AFNIC and the Internet Governance Forum's Dynamic Coalition on Internet Standards, Security and Safety (IS3C), brought together technical experts, registry operators, and internet governance stakeholders to assess the challenges of transitioning internet infrastructure - particularly DNS-related protocols - to post-quantum cryptography (PQC). Chaired by Lucien Castex, the session featured contributions from Pierre Bonis (CEO of AFNIC), Wout de Natris (IS3C coordinator), and Moritz Müller-Brus (researcher at SIDN, the .nl registry). A fourth speaker, Joao, had been planned to present IS3C's PQC report but was unable to connect during the session; de Natris offered to summarise the report's conclusions in his absence. Questions from the floor broadened the discussion into geopolitical, regulatory, and equity dimensions.

Pierre Bonis opened by clarifying the session's scope and AFNIC's stake in the subject, noting with characteristic self-deprecation that one easy answer for why AFNIC cares about PQC is that "the R&D team" needs to be kept busy. More substantively, he emphasised that AFNIC's interest lies not in building quantum computers but in understanding how quantum computing will affect those who rely on existing cryptographic infrastructure . He also took the opportunity to praise the IS3C Dynamic Coalition as an example of what the IGF can genuinely deliver, pushing back against the perception that IGF is merely a "token shop" .

---

#

Why Post-Quantum Cryptography Matters for DNS

Bonis explained that DNS relies heavily on cryptography, most visibly through DNSSEC - a protocol developed, as he put it, after the discovery of a major flaw in the DNS protocol through what he referred to tentatively as "Lafayette Kaminsky" (acknowledging he did not have the name quite right in English) . DNSSEC uses cryptographic signatures to secure DNS responses, and its deployment has been strongly recommended by ICANN . However, the cryptographic algorithms currently underpinning DNSSEC will not withstand attacks from sufficiently powerful quantum computers .

The challenge is compounded by the nature of post-quantum algorithms themselves. While stronger than their predecessors, PQC algorithms produce larger keys and signatures and require more computational time to process . This creates a significant tension with the operational demands of DNS, which handles enormous volumes of queries in very short timeframes . Bonis warned that if these performance trade-offs cannot be resolved, the introduction of PQC algorithms could have "a huge impact on the performance of the resolution in the DNS" . He therefore called for urgent testing of both the algorithms and the hardware that might accelerate the necessary mathematical operations .

In a deliberately provocative aside, Bonis raised what he himself acknowledged was "a very bad thing to say": if no viable PQC solution can be found that maintains acceptable DNS performance, one theoretical last resort would be to remove DNSSEC entirely, since doing so would eliminate the post-quantum cryptography problem for DNS . He raised this not as a recommendation but to underscore the seriousness of the performance challenge and the need for evidence-based decision-making.

##

The Absence of Empirical Evidence for DNSSEC's Benefits

Compounding the challenge, Bonis noted a striking gap in the evidence base: he had never encountered a study demonstrating the actual, measurable security benefit of DNSSEC deployment . Existing literature, he observed, either advocates for DNSSEC or reports adoption percentages, but does not compare attack rates in signed versus unsigned zones . Without such data, it becomes difficult to justify the costs and complexity of maintaining DNSSEC - let alone migrating it to post-quantum algorithms. This point resonated with Jimson Olufuye, who later suggested that ICANN should be formally asked to produce such statistics, noting that advocates in regions such as Nigeria need concrete evidence to support their mobilisation efforts .

---

#

IS3C's Work and the Governance Framing

Wout de Natris, coordinator of IS3C, provided both an organisational update and a broader conceptual reframing of the challenge. He noted that IS3C - now formally established - has produced four reports and two toolkits on internet standards deployment and policy, with the most recent focused on PQC . Since presenting this report at the IGF in 2025, IS3C has organised four workshops and webinars on the topic and established two working groups, one on DNS and one on RPKI, both of which have held their first meetings .

De Natris also highlighted an important and sobering technical development: the first encryption algorithm has already been broken by a quantum computer, "although it's very limited in size," and that as each quantum bit is added, the technology becomes more powerful - underscoring that the threat is not merely theoretical but already in motion.

De Natris then made a pivotal argument: post-quantum cryptography preparedness is not fundamentally a technical problem . Rather, it is "all about convincing those with decision power" and is a matter of "political, economic decision-making and the will to prevent social harm to come to all citizens, customers and end users" . He argued that if decision-makers act positively, technicians will receive the training and funding they need to deploy the relevant standards in time . The problem, he stressed, is that security-related internet standards such as DNSSEC and RPKI are "at best moderately well adopted to downright dismal" globally , and this must change before the quantum threat becomes acute.

He also emphasised the urgency of the timeline: "somebody could have the eureka moment tomorrow," and while no one can be prepared for tomorrow, the community should be prepared for two to three years from now, "because things are going incredibly fast." This framing gave concrete shape to the window for action.

To illustrate the stakes, de Natris used a thought experiment: he asked the audience to imagine an invention that made all locks in the world open simultaneously, then drew a direct parallel to what a sufficiently powerful quantum computer could do to all digital encryption . Audience responses ranged from going home to be with family to calling Pierre Bonis for a solution, which de Natris used to reinforce his point about the widespread lack of urgency even among specialist communities .

---

#

The Risk of a Quantum Security Divide

De Natris was explicit that the PQC transition must not replicate existing digital inequalities. He stated that "a digital security and quantum security divide must be prevented" and that "it cannot be that the western world is taking care of itself while the rest is not" . IS3C is preparing awareness-raising and training programmes to address this, but currently lacks the structural funding to operate at the required scale .

He also drew on IS3C's prior research to illustrate the dangers of fragmented, uncoordinated policy. In a study of IoT policies across 21 jurisdictions, IS3C found 442 best practices that industry was expected to adhere to, some of which were "totally contradictory" . He warned that if PQC guidance follows the same path - with every country producing a different set of rules - industry will be unable to adopt coherent standards . Coordinated action at a global or at least regional level, across stakeholder communities, is therefore essential .

---

#

Technical Assessment: DNSSEC and RPKI Readiness

Moritz Müller-Brus of SIDN offered a detailed technical assessment of where DNSSEC and RPKI stand in their PQC transition planning. By way of context, he noted that SIDN manages .nl names, of which 60% are signed with DNSSEC - a significant deployment base that gives SIDN a direct stake in the transition.

On DNSSEC, he noted that the urgency is somewhat less acute than for protocols such as TLS, because DNSSEC uses cryptography for signing and verification rather than for encrypting communications - meaning it does not face the "store now, decrypt later" threat . Nevertheless, he cautioned that algorithm transitions in DNSSEC have historically taken at least a decade or so, as demonstrated by the slow migration from RSA to elliptic curve cryptography , and that the post-quantum transition may take even longer given that PQC algorithms are not drop-in replacements - they have larger keys, larger signatures, or both .

There are, however, positive signs. The DNS community is better at changing algorithms than it once was, having successfully transitioned from RSA to ECDSA in .nl and many other TLDs . More automation is in place, the DNS root has rolled its keys at least once and is preparing to do so again, and the IETF community is increasingly in working on PQC for DNSSEC . SIDN has also created a publicly accessible test lab - open to external parties who wish to test their own DNS zones - for assessing the impact of post-quantum algorithms on DNS zone files, and is now extending its research to the validation side, examining what happens when resolvers must validate large volumes of post-quantum signatures .

Looking ahead, Müller-Brus identified several remaining challenges: the community must wait for suitable algorithms to be standardised, the DNS protocol itself may need to be modified to accommodate PQC algorithms , and incentives - including education, a sense of urgency, and possibly legislation - will be needed to drive deployment once technical solutions are available .

---

#

RPKI: A Less Mature Picture

On RPKI - the infrastructure that secures BGP routing on the internet - Müller-Brus painted a less optimistic picture . RPKI is a newer deployment than DNSSEC, has never undergone an algorithm change, and the community developing RPKI protocols is still largely focused on current operational challenges rather than future PQC requirements . There is also no clear consensus on what exactly needs to change in RPKI to achieve a PQC transition . Müller-Brus suggested that the immediate priority should be to identify the specific technical requirements for RPKI's transition - which components must change, which can remain, and what the overall requirements are - building on initial intern research at SIDN .

De Natris reinforced this concern from a governance perspective, noting that IS3C's RPKI working group members are "not discussing it" and are "not asking for us to be" . He expressed surprise that "there doesn't seem to be an overarching organisation at this point in time working on it" , and warned that the lack of urgency in the RPKI community is particularly dangerous given how quickly quantum computing is advancing .

---

#

ICANN's Evolving Position

The question of ICANN's role in PQC preparedness arose from multiple directions. Olufuye asked whether ICANN is actively working on post-quantum readiness, particularly in relation to root servers . Bonis confirmed that ICANN's engagement is recent and somewhat belated: in a public discussion just months prior, ICANN's Office of the CTO (Octo) had stated that PQC "is not the problem. We will see that later" - this being Bonis's recollection of what was said - only to reverse this position within fifteen days, declaring it "a huge problem" . Bonis suggested that ICANN had been heavily focused on the DNS root key rollover - a complex and high-stakes operation - and had only recently turned its attention to the post-quantum challenge . He affirmed that this shift is welcome, but noted that it underscores how recently even the most authoritative bodies in internet governance have begun to engage seriously with the issue.

---

#

Geopolitical Fragmentation and Regulatory Risk

The latter part of the session introduced a geopolitical dimension. Jacques Beglinger, associated with the Swiss IGF, raised the concern that competition between major powers could produce incompatible national or regional PQC standards - a "western standard," an "African standard," or a "nation standard" - mirroring broader trends of internet fragmentation . Bonis responded by reframing the fragmentation risk: the more pressing concern, he argued, is not competing standards but unequal access to the hardware capacity needed to implement PQC . He pointed to AI companies purchasing available hardware and driving up prices as a key driver of inequality, warning that this could "create a problem between big Internet players, big registries, big telcos, and smaller ones" .

Peter Koch of DENIC added a further dimension, warning that urgency combined with geopolitical competition "might lead to fragmentation actually when unwise regulation kicks in" . Specifically, if a particular PQC algorithm is deprecated or banned in one jurisdiction but used in another, cross-continental DNS interoperability could break down . He asked what the IS3C Dynamic Coalition could do to make this risk explicit and prevent it .

De Natris responded that proactive community-led testing and implementation of PQC solutions may be the best defence against poorly designed regulation, since "focusing on studying, testing and implementing post-quantum cryptography solution may prevent bad regulation" . He acknowledged that the IS3C working groups should explicitly address the fragmentation risk as a topic, and reiterated the importance of bringing diverse stakeholders into the conversation rather than allowing each community to remain in its own silo .

---

#

Future Applications and Constrained Devices

Philippe Foucart of Orange raised a forward-looking question about whether future applications - such as agentic AI running over UDP - might introduce new DNS security requirements, particularly around authenticity and integrity of messages . Müller-Brus acknowledged the concern but noted that it is not currently a primary research focus, largely because the assumption is that PQC validation will occur at recursive resolvers rather than at the device level, meaning constrained devices and future applications would communicate with these resolvers rather than performing validation themselves .

---

#

Conclusions and Call to Action

The session closed with a broad call for cross-stakeholder collaboration, urgency, and coordinated global action. De Natris summarised the challenge: most stakeholders are "looking at somebody else to start the action," which historically leads to collective inaction and mutual blame . He urged all interested parties to join IS3C's working groups and contribute to the coordinated effort . Müller-Brus concluded that DNSSEC is further along than RPKI in its PQC transition, but that neither is ready, and that the technical, governance, and incentive challenges ahead are substantial . Bonis closed with characteristic dry humour, noting that "silos might be very safe for quantum, in particular on the moon" - a wry acknowledgement that isolation is not a viable strategy.

The session's report and related materials were made available on the IS3C website and AFNIC's session page , and the working groups on DNS and RPKI were identified as the primary vehicles for taking the work forward. The overarching message was clear: the window for preparation remains open, but it is narrowing, and the time for coordinated action - technical, political, and institutional - is now.

Lucien Castex
Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. Maxime. so welcome everyone to this session on both quantum cryptography as we have people online and in the room we'll be using microphones also if you have questions etc you have one just behind you I can style I would say so you can you
Pierre Bonis
can take it to just use it this session is called post quantum preparing the internet for post quantum cryptography it's organized by AFNIC the French internet and the dynamic coalition on internet standard security and safety is 3c I would like first to give the floor to the CEO of AFNIC Pierre Bonis to set the stage thank you very much Lucien welcome everybody very happy to be here with you so this is I'm gonna not introduce the quantum not me but maybe there is a reason why this is a subject of interest for AFNIC as a registry and first of all thank for leading the dynamic coalition for now a few years and this is a very five years this is a very important work we we are fully dedicated to it and by the way even if it's not exactly the main point of this session I cannot stress enough the fact that dynamic coalitions in general and IS3C in particular are examples of what IGF can create. A lot of people think that IGF is not delivering. It's a token shop. I think Dynamic Coalitions shows the very opposite of it. It's a way of gathering expertise and working in an intersectional... ...very important topics in the long run. And it has worked for several years, and this is something we have to bear in mind, maybe in preparation of the next IGF in Nairobi, to remind everyone that Dynamic Coalitions are a very good tool. Now, once I've said that, why do we care about post -cum -to -cryptography? The first... The first and easy answer would be the R &D team, and I have to keep them busy. But that would be very short. And by the way, we will never be a major player of quantum, because we don't have the money to get involved in that. So this session is not about quantum. It's about post -quantum cryptography, which means that we are talking from the side of the people who are effect, not on the side of the people who are building the computers that would be the quantum computers. This is the first thing that is very important, because even my brilliant idea and R &D team is not able at all. to deliver anything that makes really sense about quantum computing, at least for us. So why does it matter? It matters because DNS is using cryptography. A lot of people know that C cryptography in other protocols are very visible, just like HTTPS or this high layer cryptography, but DNS uses it also. And I think the most well -known way of using cryptography in the DNS is DNSSEC. DNSSEC is a way of securing the DNS with cryptography, and it has been developed. So it's a way of doing it. So it's a way of doing it. after the discovering of a major flow in the DNS protocol through Kaminsky, Lafayette Kaminsky, I'm sorry, I don't have it in English. Since then, this is highly recommended, and especially by ICANN, to sign and to have DNSSEC. The third DNSSEC, as for any other cryptography or signed protocol, the crypto algorithm that we have currently will not resist quantum. So we have to deploy some other ways of security. That will be... post -quantum compliant or post -quantum ready. And it happens that for now, these but they are stronger, of course, but longer and they take more time to work. And as the DNS is a protocol with a lot of queries in a very, very short time, you know, the introduction is for people like me. I mean, it's a very basic introduction. You will have specialists who will say very, very, very precise things after me. As there are a lot of queries and this is done in a very short time, if we have to use this kind of algorithm, it may be a problem in terms of latency, in terms of and it may, in a way, if we are not prepared to that. have a huge impact on the performance of the resolution in the DNS. So we have to get prepared. We have to test this algorithm. We have to test the hardware that can help us to do the math quicker. And maybe we have to think about alternatives if we see that there are huge problems and maybe to end this introduction, why it matters to us is that one way of doing it, and I know that this is a little bit scandalous to say that, but I'm not saying that we are aiming to do that, but one way of doing it, if there are no solutions, if we see that it's going to be a problem, it's going to be very hard. to maintain a certain level of performance with the DNS would be to remove DNSSEC. Because if we remove DNSSEC, we don't have the post -cryptography problem. So that's a very bad thing to say. But I would just say that I've never seen any study on really what has been the effect of the deployment of DNSSEC. I've just seen things or papers saying you have to do it. And papers saying, oh, good, you've done it. And there are this amount of percentage of domain names or zones that are signed. And that's good. Everyone is convinced that it's a very important thing. But I've never seen it. If people in the room have this information, I'm very interested. The reason, for instance, between zones that are signed and zones that are not signed... and the number of men in the middle of attack of this kind that we had in the zone that were not signed compared to the one in the zone that were signed. So when I say that this is an option, I mean, it's a nuclear -bottom option, of course, but this is something that if we are not
Lucien Castex
Thank you very much. Strong statement. So now I understand the session is not about quantum. I'm a bit disappointed, but well. I'll give the floor to Wout. Wout, what can you say about the work and the R &D that has been done in the past few months? Well, is it working? Yes? Okay. I think Joao was going to say more about the work that's been done. I'm going to set a little bit more stage and also tell a little bit about what we've done.
Wout de Natris
So my name is Wout van Atres, from the Netherlands, a board consultant based in the Netherlands, and the coordinator of the Internet Governance Forum, Dynamic Coalition, IS3C, or Internet Standard Security and Safety. And thank you for the kind words that you shared, Pierre. I can say nowadays that we're formally running a very important and important work, and I think that's going to be a very important and important part of the work. I think that's going to be a very important part of the work. I think that's going to be a very important part of the work. I think that's going to be a very important part of the work. I think that's going to be a very important part of the work. I think that's going to be a very important part of the work. I think that's going to be a very important part of the work. I think that's going to be a very important part of the work. earlier this year. Our main goal is to get security -related internet standards and ICT best practices massively deployed, something most of these standards still are not in many parts of the world. Of course, both quantum cryptography standards. Now, we'll be brief about our work, but yes, we've been delivering reports in the past four or five years. We have produced four reports and two toolkits on internet standards deployment and policy. The latest is on PQC and it will be presented later by my colleague Joao Moreno -Focao. On this topic, since we presented the report at the IGF in 2025, we've organized four different workshops of webinars on this. We're at other events presenting on the results and we've seen we've started two working groups, one on DNS and one on RPKI. and both had had their first meeting. But let me start with doing a thought experiment with you. And I'm going to tell you, gentlemen over there, because you may be closest to the microphone, to answer my question in the microphone. I'm doing a thought experiment. Imagine a situation in which an invention would make all locks in the world open simultaneously. Because
Audience Member 1
Family.
Wout de Natris
Family. So, yeah. You'd go home, right? Thank you very much. And I'll come back to you in a moment. So, this is hypothetical, right? There's no way we can open every lock simultaneously every time. But what happens when the first powerful enough quantum computer is active? We don't know by whom. We don't know by what. But all of a sudden, everything digital, the encryption is broken and it's accessible. So where would you go first then? and what would you have to save if your car drives away by itself whatever what would you do then first
Audience Member 2
I'm not sure I'm not sure I would see this as so negative I would say I would stay home I have
Audience Member 3
ok there is a question about energy would it have an impact on energy as well what can you do
Wout de Natris
thank you I think that's the right answer what can you do where do you start do you start with your mother
Audience Member 4
if the phone works I would call Pierre for getting a solution
Wout de Natris
do you know how to get his email thank you thank you so So in other words, this is something that is not happening yet, but we know that the first encryption algorithm is already broken by a quantum computer, although it's very limited in size. That quantum bit is added, makes it more powerful. So fortunately, we still have time to do this, but also we do know that standards deployment is not something which has an extremely good reputation around the world at this moment. So that is something we need to change. And others will tell more about the technical current situation and what steps to take. However, this is not a technical issue. And everybody may think it is, but it's not a technical issue. Why? It's all about convincing those with decision power that they can do this. It is secure. It's about political, economic decision -making and the will to prevent social harm to come to all citizens, customers and end users, be they individuals or organizations. If decision -makers decide positively, the technicians will get the training and they will get the funding they need to deploy the set standards in time. But is this common practice? And was it? The new generation security -related standards like DNSSEC and RPKI and ICT best practices as for example the OWASP top 20 or 25 on websites are at best moderately well adopted to downright dismal. Now this has to change. IS3C is currently preparing for awareness raising and training programs but lacks the structural funding to make this happen at the right scale. to secure the world a digital security and quantum security divide must be prevented it cannot be that the western world is taking care of itself while the rest is not so quantum will most likely bring many positive outcomes in connections with AI and whatever because it will be power that is unleashed for the positive as well but we must first prevent mayhem financial mayhem etc. from happening so we have our work cut out for us but we can't do this in isolation and with me I mean every single stakeholder in this room and beyond this room but only across stakeholder communities and I'll give one example from our past work we've compared IOT policies in our first report we had 21 jurisdictions that we found that had an IOT policy wrote In these 21 jurisdictions, we found 442 best practices that the industry had to adhere to, 442 of which some were totally contradictory. So if you want to do the same with this post -quantum cryptography and advices around it, then industry can never adopt it if you have in every country a different set of rules. And that is what I mean we can't do this in isolation. This has to be coordinated at an ideally global level or at least regional and across stakeholder communities so everybody is clear on the steps. We see in Avnik have decided to start with the domain name and routing sectors, but many, many others will have to follow suit. Just think of IoT devices, devices in cars, whatever you have in your house working on an Internet connection, it all needs to be secured. So I would say if you're interested, join us now. We're here, so just speak to us. And from there, I hand over to Moritz,
Lucien Castex
but first to Lucien, of course. Thank you very much. Thank you, Wout. No transition. I'll give the floor to Moritz and then to our colleague Yao
Moritz Müller-Brus
online. Moritz, you have the floor. Thank you. So I work for SLM. SLM is the registry of DLNL. So we are in a quite similar situation as our colleagues from AFN. Main names, out of which 60 % signed with DNSSEC. So DNSSEC and the future of DNSSEC is close to our heart. But also the RPKI is close to our heart, and you might wonder why this is the case. But, of course, DNS relies also on the routing on the Internet, and therefore the security and reliability of routing is also at our heart, and therefore also RPKI. So we have a transition to post -content crypto at some point in time. I would like to share a bit my view or our view on the current state of protocols to post -quantum crypto where we are currently, where we are currently working on and also what still needs to be done let's start with DNSSEC so we all know that there is some sort of urgency to transition to post -quantum crypto for DNSSEC but of course it's not as urgent as with for example TLS in DNSSEC cryptography is being used for signing and verification which means we do not have the problem of store now, decrypt later so we might still have some time however we know from the experience in the past that transitioning to a new algorithm in DNSSEC does take quite some time we've seen that for classical algorithms so when we start from RSA to elliptic curve cryptography this took at least a decade or so before we got reasonable deployment of this new algorithm But in case of post -contra -crypto, urgency might of course help there. Let's start with the things that are maybe not as good in DNSSEC at the moment. As we've already heard, the post -contra -crypto algorithms are probably not dropped in replacement as they have been with transitioning from RSA to ECDSA, for example. They have larger keys, larger signatures, or maybe both, and therefore transitioning might take even more time if we do not get all behind this transition. Also, currently we're not sure yet which of these post -contra -crypto algorithms might be actually suitable for DNSSEC. Some of them are already standardized, so this might be interesting. They're still not standardized, and so we still have to kind of wait for their standardization. But I think not everything is bad when it comes to transitioning to post -contra -crypto and DNSSEC. today we are better changing algorithms so we have changed algorithms in the past for .nl we have transitioned from RSA to ECDSA and many of the other CCDLDs and TLDs have done so as well we have more automation in place so we are a bit more comfortable with doing these processes in automatic and the roots, so the top of the DNS also has rolled its keys at least once and will roll it again this year but of course it's not rolled over yet but at least we have tested the exchange of the keys so I think this is a good sign and what also makes me personally hopeful is that the community, at least the technical community from my perspective is relatively working on transitioning DNSSEC to post -contra crypto so and I think that's a good sign meetings at the ITF where we have a growing number of participants actively working and presenting and sharing their thoughts on how we can make DNSSEC quantum safe and also at SAN we're quite busy with this so in the past we've did research on the impact of signing algorithms on creating new zone files we've created a test lab for that which you can also access so if you are interested in seeing what the impact might be on a certain post quantum crypto algorithm on your DNS zone then you can test that also we're now looking into the other side so we're looking into the validation side what might be the impact when they would have suddenly have to validate a lot of post quantum crypto algorithms so also here there's already some work going on so what might be the next steps and I think there's I agree with what Wout said so we have to figure out a lot of technical details still but I think but there might not be only technical challenges afterwards. So we have to wait for an algorithm that is suitable and we might then even have to modify the DNS protocol. Also will take time. But when the technical solutions are there, we have to get incentives to deploy these new algorithms as well. Well, as I said, we used financial incentives in the past to motivate the deployment of DNSSEC, but we will also probably need education. We need a feel of urgency for the people who are in charge of this and maybe even legislation, but I'm a bit more careful with this statement. For DNSSEC, I would say I'm slightly positive where we are currently for RPKI, which is the infrastructure, infrastructure that helps us to secure the BGP on the internet. the picture is not as clear yet I would say so compared to DNSSEC RPKI or at least the deployment of RPKI is still relatively new so I have the feeling that the people developing the RPKI protocols they are still more busy with working on and not so much with problems that might appear in the future also there we have never changed an algorithm before so I think there are procedures for that but they still have to be tested at some point in time and we are still just not quite sure yet what actually needs to happen in RPKI to transition to post -contra crypto so overall there is less inertia compared to DNSSEC so I would suggest here a possible next step is to get first of all the technical and maybe similar as we did with DNSSEC to identify the problems that we actually have in RPKI when transitioning to post -contra crypto which are the parts that have to change, which are the parts that have to keep, which are the requirements actually. And we had an intern that did quite some good work on that, but I think now it's the time to take the next steps. So to summarize, I think DNSSEC is further than RPKI, but of course we're
Lucien Castex
Thank you. Moritz, I would like to give the floor online to Jao. Jao, can you hear us? Can you... I'll check with my colleague on the technical side. Is the last speaker connected to the Zoom? I'll check with the Zoom interface.
Jacques Beglinger
you might have any to ask questions if you have or if you have any remarks sure take the mic Sarah hello I'm Jacques Mecklinger I'm from Switzerland head of Swiss IGF etc and my sense is when I look at the fragmentation of the threat of fragmentation of the internet at large due to geopolitics how how close are we to a fragmentation also of these technical standards or in other terms will we end up in the end with a nation standard, with a western standard, with an African standard, things like that, that some kind of competition of standards as we may come closer to even acerbated competition of systems
Lucien Castex
Do we take several questions and then after?
Jimson Olufuye
Okay. Thank you very much. My name is Jim Sinalufuye, a contemporary consultant in Africa, Africa Alliance based in Abuja, Nigeria. This doggo, Pierre, talked about the gap in statistics. Okay, DNSSEC, we have it, but we don't know the effect if we don't have it. don't think it's an important statistics we need to get and shouldn't we ask ICANN to give us that statistics because it's good to know what is going on so that we can really fully justify because we did some roadshow in Lagos some time back I made a lot of mobilization so we should have something to show that yes it's actually quite positive secondly I don't know ICANN should be concerned about this post -quantum too because of the routes and what have you so any idea ICANN is working in that regard thank
Speaker 1
based in Abuja, Nigeria. This dog will appear. Talk about the gap in statistics. That, okay, DNA -seq, we have it, but we don't know the effect if we don't have it. Don't think it's an important statistic we need to get, and shouldn't we ask ICANN to give us that statistic? Because it's good to know what is going on so that we can really fully justify because we did some roadshow in Lagos some time back. I made also a lot of mobilization. So we should have something to show that, yes, it's actually quite positive. Then secondly, I don't know whether ICANN. ICANN should be concerned about this post -quantum too because of the roots servers and what have you. So any idea, ICANN is working? That we got?
Moderator
Thank you. Anybody have questions before? Sure. Since we have time.
Philippe Foucart
I'm with Orange. On a different topic, I was wondering, because Pierre mentioned the fact that, moving forward, DNSSEC may be somewhat redundant with other mechanisms and higher levels. We're hearing that there are also other applications which may not provide that level of security, possibly running on UDP, et cetera, whereby maybe authenticity and integrity of the messages would be required for those applications. I'm thinking about genetic AI, for example. It's still a pie in the sky at the moment. But I'm just wondering whether you also gave some thought about how those future, applications may... and be robust towards change in the security of the DNS, if I'm making sense. Thank you.
Moderator
So, Pierre, do you want to jump in?
Pierre Bonis
Yeah, thank you. Maybe I will leave shortly the question of Philippe to my colleagues because I'm not very sure that I want to answer. And anyway, the answer is going to be partial to each and every question that was asked. As for the fragmentation, thank you very much for the question. I think more it stays that. This is, I mean, this post -quantum cryptography is not only about DNSSEC. It's about other core functions or core. Cryptography challenges that we have. Talking only about the Internet layer, not the other layers. So that might be a question of hardware capacity. So it's not one standard for some country, one other standard for another one. It's how are we able to equip ourselves. And to me, this is a very important question that you raise. It's much bigger than the question of different standards. It may be the question of access to the hardware capacity. And by the way, it's not only about HSM. For instance. Or this kind of hardware. It's about the scarcity, the price rising up, the fact that some AI giants are buying everything, may, at the end of the day, create a problem between, let's say, big Internet players, big registries, big telcos, and smaller ones. And so this is something that we have in mind. And I think that would be useful to have it, because I fear that at one point... people decide to unsign. That's why I said that patient. So I think every statistic that can show the actual utility, the actual pertinence of DNSSEC is worth doing now. And not having said that, if IETF said it, if ICANN said it, it's in the Bible. No. You have to show that we have decided to do something a year ago and we are not able to say to the world we were right to do that. It was useful and we can give evidence. And I think this is a huge problem. And as a on the question of is ICANN preparing itself for this post -consumption cryptography challenge? Yes. But that's very recent. And I remember that with Regis Massé, our CTO, we had a discussion with Octo. It was not a bilateral discussion by the way. It was a public discussion in ICANN. And a few months ago, Octo said, oh, this is not the problem. We will see that later. And 15 days after, they said, oh, this is a huge problem. We are going to... So, I mean, there was a shift. I think on the ICANN and maybe on the IANA function, they are very much concerned, I mean, focused on the rollover and, as I said, on the huge that they have to do this year because there's a lot of And even if people sometimes laugh about it and they say, okay, it takes a lot of time for Yana to do that, but if they fail, it's a huge problem for everyone. So maybe they were very focused on it, but now they realize and they recognize that they have to work on the post -quantum too. So this is good
Wout de Natris
Thank you. University is willing to work, but they all say there's nothing we can do at this point because the message was there is no algorithm in theory about deploying. it. And then I think you got the message wrong because the algorithm will be there and at least you can identify the challenges you're going to run into and have them ready in a roadmap or something. On the RPKI side, the only thing I heard, our members are not discussing it. They're not asking for us to be active. So in other words, there doesn't seem to be an overarching organization at this point in time working on it. This is something which surprises me, but that's just me. But there is a lack of urgency that is missing. There's a lack of urgency because let's face it, somebody could have the eureka moment tomorrow. And of course, nobody can be prepared for tomorrow, whatever we do. But we should be prepared for two years or three years from now because things are going incredibly fast. and I'm not seeing that urgency in most people that I'm talking to, most are looking at somebody else to start the action and that is usually where everybody blames somebody else in the end so I can say that we see the urgency so don't get me wrong but there is a lack of urgency I'll ask again if Joao is there now I can say something about the conclusion in the report but I can't explain what exactly they've done give the floor to Moritz maybe to bump in that and we'll link the report to the session so that everyone can actually access it if needed and the further work that we want to do Moritz
Moritz Müller-Brus
I can answer a bit Philippe's question I guess it's about the size of packets that we might get and that constrained devices might have problems But from my perspective as a researcher, people think about it, but it's definitely not the main concern. So I think there's something that we keep in our minds, but the assumption probably is also that validation is taking place at recursive resolvers, and these recursive resolvers will take care of it, and these constrained devices will then talk to these recursion themselves at all. So I think this is why this topic doesn't have such a high priority, unfortunately.
Peter Koch
Hi there. My name is Peter Koch. I work for DNIC, which is another DNS top -level domain name registry, and I wanted to advertise DNS -ORG as the DNS operator community, where lots of people look into this. When this is about how to do the transport and stuff, there are a lot of incentives to change that anyway for a couple of other very technical reasons that I'm not going into here. But the reason to get to the microphone was inspiring a bit the urgency that Wout mentioned together with geopolitics and competition in algorithms might lead to fragmentation actually when unwise regulation kicks in. And this is because you hadn't mentioned that explicitly, but I think it's very important to understand that this is to be sure. Make sure that the DNS can talk from continent to continent and across all those. So if we have a particular algorithm arising in one place, which is deprecated, say, or banned or something in another place, then obviously. that interoperability will not be there and maybe you can reflect on what your dynamic coalition might have done to make that clear. Thank you.
Wout de Natris
Thank you very much Peter. When you say DINIC is another registry you should say DINIC is the registry. It's not just another one. But short answer. We all know that regulation comes when regulators or legislators first of all discover a problem and but luckily because sometimes there is regulation without a problem and this is a problem discover a problem secondly think that no one cares or no one has taken the good steps to resolve this problem so I would say that focusing on studying testing and implementing post -quantum cryptography solution may prevent bad regulation and if as a community I will see that later then we are in grave danger of having regulation that cannot be a good one because this is still a work in progress so that was my answer thank you we have not looked into that yet because we looked at the policies of 2025 but yes if we have this working group then this should be one of the topics we are discussing quite obviously and I may 442 best practices in 21 different jurisdictions and about the necessity to not isolate ourselves in silos but to talk in a broader sense and that can only happen when you bring in other people and I think from the answers that we have been getting so far people have the tendency to go into their silo and wait for others to act so I think that is what needs to be broken there needs to be a door there needs to be a bridge to the other silo and I think that is something that the Internet Governance Forum could provide and whether this dynamic coalition is able to do that that is going to be an experiment but we doubt in favor of inviting other people to these discussions to prevent exactly what you've been mentioning, Peter. So that's the best answer I can give you at this
Moderator
Thank you, everyone. I think we are at the end of the session.
Pierre Bonis
I was thinking the silos might be very safe for both quantum, you know, in particular on the moon.
Moderator
Thank you, Pierre. Thank you, Moritz. Thank you, Wout. And thank you, everyone, for the questions and the thoughts. We will post on the session page the report that Wout mentioned, as well as obviously on the I3C website and AFNIC as well. Thank you, everyone, and see you around in the WSS.

Disclaimer: This is not an official session record. DiploAI generates these resources from audiovisual recordings, and they are presented as-is, including potential errors. Due to logistical challenges, such as discrepancies in audio/video or transcripts, names may be misspelled. We strive for accuracy to the best of our ability.