This session focused on the challenges of preparing internet infrastructure - particularly DNS and routing security - for the era of post-quantum cryptography (PQC).
Pierre Bonis, CEO of AFNIC, explained that DNS relies heavily on cryptography through DNSSEC, and that current cryptographic algorithms will not withstand quantum computing . He warned that post-quantum algorithms, while more secure, are larger and slower, potentially creating significant latency and performance issues for DNS resolution . In an extreme scenario, he raised the controversial possibility that DNSSEC could be removed if no viable PQC solution is found, though he acknowledged this would be a deeply undesirable outcome . He also noted a lack of empirical evidence demonstrating the concrete security benefits of DNSSEC deployment, calling for better statistics .
Wout de Natris, coordinator of IS3C, framed the issue as fundamentally a political and economic challenge rather than a purely technical one, stressing that decision-makers must be convinced to act before a quantum breakthrough renders current encryption obsolete . He highlighted the risk of a "digital security and quantum security divide," warning that fragmented, contradictory national regulations - as seen with IoT policies across 21 jurisdictions producing 442 often-contradictory best practices - could prevent coherent global adoption of PQC standards .
Moritz Müller, from SIDN (the .nl registry), provided a technical assessment, noting that DNSSEC is further along in PQC transition planning than RPKI, though neither is ready . He observed that algorithm transitions in DNSSEC have historically taken a decade or more, and that suitable PQC algorithms for DNSSEC are still being standardised . For RPKI, he noted there is less community momentum and no prior experience of algorithm migration .
Participants raised concerns about geopolitical fragmentation leading to incompatible national standards , the need for ICANN to engage more urgently with PQC , and the risk that poor regulation could undermine interoperability . The session concluded with a broad call for cross-stakeholder collaboration, urgency, and coordinated global action to avoid the fragmentation of internet security standards .
Overall Purpose
- The discussion aims to raise awareness about the urgent need to prepare internet infrastructure - particularly DNS-related protocols such as DNSSEC and RPKI - for the transition to post-quantum cryptography (PQC). Organised by AFNIC and the IS3C Dynamic Coalition, the session brings together technical experts, policymakers, and internet governance stakeholders to assess the current state of PQC readiness, identify gaps, and encourage coordinated global action.
- --
Major Discussion Points
- The threat that quantum computing poses to current cryptographic standards, especially DNSSEC: Current cryptographic algorithms used in DNS security will not withstand quantum computing attacks. Pierre Bonis explained that post-quantum algorithms, while stronger, are larger and slower, potentially creating significant latency and performance issues for DNS resolution. He provocatively raised the "nuclear option" of removing DNSSEC entirely if no viable PQC solution is found, whilst acknowledging this would be deeply undesirable. - The uneven state of PQC readiness between DNSSEC and RPKI: Moritz Müller-Brus noted that DNSSEC is further along in its PQC transition than RPKI, benefiting from prior algorithm migrations and growing community engagement at the IETF. RPKI presents a less clear picture - it is a newer deployment, has never undergone an algorithm change, and lacks the same level of urgency or community focus. He suggested that identifying RPKI's specific transition requirements should be a priority next step. - The lack of urgency and the risk of a "wait-and-see" culture: Wout de Natris stressed that standards deployment has a poor track record globally, and that most stakeholders are waiting for others to act rather than taking initiative. He warned that a powerful enough quantum computer could break all current encryption simultaneously, and that the window for preparation - whilst still open - is narrowing rapidly. He also highlighted that IS3C lacks the structural funding needed to drive awareness and training at the necessary scale. - The risk of fragmentation - both technical and geopolitical: Jacques Beglinger raised the concern that geopolitical competition could lead to incompatible national or regional PQC standards. Peter Koch reinforced this, warning that unwise regulation driven by urgency could result in algorithms being banned or deprecated in some jurisdictions but not others, breaking cross-border DNS interoperability. Wout de Natris responded that proactive community-led testing and implementation of PQC solutions may help prevent poorly designed regulation. - The need for evidence-based justification of DNSSEC and coordinated global policy: Pierre Bonis highlighted a significant gap in empirical data demonstrating the real-world security benefits of DNSSEC, noting he had never seen comparative studies of attack rates in signed versus unsigned zones. Jimson Olufuye echoed this, suggesting ICANN should be asked to provide such statistics. Wout de Natris further argued that PQC policy must be coordinated globally - not siloed by country - pointing to a previous finding of 442 contradictory best practices across just 21 jurisdictions as a cautionary example. ---
Overall Tone
- The discussion opens with an informative and measured tone, as speakers set the technical and organisational context for PQC challenges. It then shifts to a more urgent and cautionary register, particularly when Wout de Natris uses a thought experiment about all digital locks opening simultaneously to convey the stakes of quantum vulnerability. By the latter half of the session, the tone becomes notably more concerned and candid, with speakers openly acknowledging institutional inertia, funding shortfalls, and the danger of fragmentation. Overall, the discussion is constructive and collaborative, ending with a call to action for broader stakeholder engagement rather than despair.
Expanded Summary: Preparing the Internet for Post-Quantum Cryptography
#
Session Overview and Context
This session, organised by AFNIC and the Internet Governance Forum's Dynamic Coalition on Internet Standards, Security and Safety (IS3C), brought together technical experts, registry operators, and internet governance stakeholders to assess the challenges of transitioning internet infrastructure - particularly DNS-related protocols - to post-quantum cryptography (PQC). Chaired by Lucien Castex, the session featured contributions from Pierre Bonis (CEO of AFNIC), Wout de Natris (IS3C coordinator), and Moritz Müller-Brus (researcher at SIDN, the .nl registry). A fourth speaker, Joao, had been planned to present IS3C's PQC report but was unable to connect during the session; de Natris offered to summarise the report's conclusions in his absence. Questions from the floor broadened the discussion into geopolitical, regulatory, and equity dimensions.
Pierre Bonis opened by clarifying the session's scope and AFNIC's stake in the subject, noting with characteristic self-deprecation that one easy answer for why AFNIC cares about PQC is that "the R&D team" needs to be kept busy. More substantively, he emphasised that AFNIC's interest lies not in building quantum computers but in understanding how quantum computing will affect those who rely on existing cryptographic infrastructure . He also took the opportunity to praise the IS3C Dynamic Coalition as an example of what the IGF can genuinely deliver, pushing back against the perception that IGF is merely a "token shop" .
---
#
Why Post-Quantum Cryptography Matters for DNS
Bonis explained that DNS relies heavily on cryptography, most visibly through DNSSEC - a protocol developed, as he put it, after the discovery of a major flaw in the DNS protocol through what he referred to tentatively as "Lafayette Kaminsky" (acknowledging he did not have the name quite right in English) . DNSSEC uses cryptographic signatures to secure DNS responses, and its deployment has been strongly recommended by ICANN . However, the cryptographic algorithms currently underpinning DNSSEC will not withstand attacks from sufficiently powerful quantum computers .
The challenge is compounded by the nature of post-quantum algorithms themselves. While stronger than their predecessors, PQC algorithms produce larger keys and signatures and require more computational time to process . This creates a significant tension with the operational demands of DNS, which handles enormous volumes of queries in very short timeframes . Bonis warned that if these performance trade-offs cannot be resolved, the introduction of PQC algorithms could have "a huge impact on the performance of the resolution in the DNS" . He therefore called for urgent testing of both the algorithms and the hardware that might accelerate the necessary mathematical operations .
In a deliberately provocative aside, Bonis raised what he himself acknowledged was "a very bad thing to say": if no viable PQC solution can be found that maintains acceptable DNS performance, one theoretical last resort would be to remove DNSSEC entirely, since doing so would eliminate the post-quantum cryptography problem for DNS . He raised this not as a recommendation but to underscore the seriousness of the performance challenge and the need for evidence-based decision-making.
##
The Absence of Empirical Evidence for DNSSEC's Benefits
Compounding the challenge, Bonis noted a striking gap in the evidence base: he had never encountered a study demonstrating the actual, measurable security benefit of DNSSEC deployment . Existing literature, he observed, either advocates for DNSSEC or reports adoption percentages, but does not compare attack rates in signed versus unsigned zones . Without such data, it becomes difficult to justify the costs and complexity of maintaining DNSSEC - let alone migrating it to post-quantum algorithms. This point resonated with Jimson Olufuye, who later suggested that ICANN should be formally asked to produce such statistics, noting that advocates in regions such as Nigeria need concrete evidence to support their mobilisation efforts .
---
#
IS3C's Work and the Governance Framing
Wout de Natris, coordinator of IS3C, provided both an organisational update and a broader conceptual reframing of the challenge. He noted that IS3C - now formally established - has produced four reports and two toolkits on internet standards deployment and policy, with the most recent focused on PQC . Since presenting this report at the IGF in 2025, IS3C has organised four workshops and webinars on the topic and established two working groups, one on DNS and one on RPKI, both of which have held their first meetings .
De Natris also highlighted an important and sobering technical development: the first encryption algorithm has already been broken by a quantum computer, "although it's very limited in size," and that as each quantum bit is added, the technology becomes more powerful - underscoring that the threat is not merely theoretical but already in motion.
De Natris then made a pivotal argument: post-quantum cryptography preparedness is not fundamentally a technical problem . Rather, it is "all about convincing those with decision power" and is a matter of "political, economic decision-making and the will to prevent social harm to come to all citizens, customers and end users" . He argued that if decision-makers act positively, technicians will receive the training and funding they need to deploy the relevant standards in time . The problem, he stressed, is that security-related internet standards such as DNSSEC and RPKI are "at best moderately well adopted to downright dismal" globally , and this must change before the quantum threat becomes acute.
He also emphasised the urgency of the timeline: "somebody could have the eureka moment tomorrow," and while no one can be prepared for tomorrow, the community should be prepared for two to three years from now, "because things are going incredibly fast." This framing gave concrete shape to the window for action.
To illustrate the stakes, de Natris used a thought experiment: he asked the audience to imagine an invention that made all locks in the world open simultaneously, then drew a direct parallel to what a sufficiently powerful quantum computer could do to all digital encryption . Audience responses ranged from going home to be with family to calling Pierre Bonis for a solution, which de Natris used to reinforce his point about the widespread lack of urgency even among specialist communities .
---
#
The Risk of a Quantum Security Divide
De Natris was explicit that the PQC transition must not replicate existing digital inequalities. He stated that "a digital security and quantum security divide must be prevented" and that "it cannot be that the western world is taking care of itself while the rest is not" . IS3C is preparing awareness-raising and training programmes to address this, but currently lacks the structural funding to operate at the required scale .
He also drew on IS3C's prior research to illustrate the dangers of fragmented, uncoordinated policy. In a study of IoT policies across 21 jurisdictions, IS3C found 442 best practices that industry was expected to adhere to, some of which were "totally contradictory" . He warned that if PQC guidance follows the same path - with every country producing a different set of rules - industry will be unable to adopt coherent standards . Coordinated action at a global or at least regional level, across stakeholder communities, is therefore essential .
---
#
Technical Assessment: DNSSEC and RPKI Readiness
Moritz Müller-Brus of SIDN offered a detailed technical assessment of where DNSSEC and RPKI stand in their PQC transition planning. By way of context, he noted that SIDN manages .nl names, of which 60% are signed with DNSSEC - a significant deployment base that gives SIDN a direct stake in the transition.
On DNSSEC, he noted that the urgency is somewhat less acute than for protocols such as TLS, because DNSSEC uses cryptography for signing and verification rather than for encrypting communications - meaning it does not face the "store now, decrypt later" threat . Nevertheless, he cautioned that algorithm transitions in DNSSEC have historically taken at least a decade or so, as demonstrated by the slow migration from RSA to elliptic curve cryptography , and that the post-quantum transition may take even longer given that PQC algorithms are not drop-in replacements - they have larger keys, larger signatures, or both .
There are, however, positive signs. The DNS community is better at changing algorithms than it once was, having successfully transitioned from RSA to ECDSA in .nl and many other TLDs . More automation is in place, the DNS root has rolled its keys at least once and is preparing to do so again, and the IETF community is increasingly in working on PQC for DNSSEC . SIDN has also created a publicly accessible test lab - open to external parties who wish to test their own DNS zones - for assessing the impact of post-quantum algorithms on DNS zone files, and is now extending its research to the validation side, examining what happens when resolvers must validate large volumes of post-quantum signatures .
Looking ahead, Müller-Brus identified several remaining challenges: the community must wait for suitable algorithms to be standardised, the DNS protocol itself may need to be modified to accommodate PQC algorithms , and incentives - including education, a sense of urgency, and possibly legislation - will be needed to drive deployment once technical solutions are available .
---
#
RPKI: A Less Mature Picture
On RPKI - the infrastructure that secures BGP routing on the internet - Müller-Brus painted a less optimistic picture . RPKI is a newer deployment than DNSSEC, has never undergone an algorithm change, and the community developing RPKI protocols is still largely focused on current operational challenges rather than future PQC requirements . There is also no clear consensus on what exactly needs to change in RPKI to achieve a PQC transition . Müller-Brus suggested that the immediate priority should be to identify the specific technical requirements for RPKI's transition - which components must change, which can remain, and what the overall requirements are - building on initial intern research at SIDN .
De Natris reinforced this concern from a governance perspective, noting that IS3C's RPKI working group members are "not discussing it" and are "not asking for us to be" . He expressed surprise that "there doesn't seem to be an overarching organisation at this point in time working on it" , and warned that the lack of urgency in the RPKI community is particularly dangerous given how quickly quantum computing is advancing .
---
#
ICANN's Evolving Position
The question of ICANN's role in PQC preparedness arose from multiple directions. Olufuye asked whether ICANN is actively working on post-quantum readiness, particularly in relation to root servers . Bonis confirmed that ICANN's engagement is recent and somewhat belated: in a public discussion just months prior, ICANN's Office of the CTO (Octo) had stated that PQC "is not the problem. We will see that later" - this being Bonis's recollection of what was said - only to reverse this position within fifteen days, declaring it "a huge problem" . Bonis suggested that ICANN had been heavily focused on the DNS root key rollover - a complex and high-stakes operation - and had only recently turned its attention to the post-quantum challenge . He affirmed that this shift is welcome, but noted that it underscores how recently even the most authoritative bodies in internet governance have begun to engage seriously with the issue.
---
#
Geopolitical Fragmentation and Regulatory Risk
The latter part of the session introduced a geopolitical dimension. Jacques Beglinger, associated with the Swiss IGF, raised the concern that competition between major powers could produce incompatible national or regional PQC standards - a "western standard," an "African standard," or a "nation standard" - mirroring broader trends of internet fragmentation . Bonis responded by reframing the fragmentation risk: the more pressing concern, he argued, is not competing standards but unequal access to the hardware capacity needed to implement PQC . He pointed to AI companies purchasing available hardware and driving up prices as a key driver of inequality, warning that this could "create a problem between big Internet players, big registries, big telcos, and smaller ones" .
Peter Koch of DENIC added a further dimension, warning that urgency combined with geopolitical competition "might lead to fragmentation actually when unwise regulation kicks in" . Specifically, if a particular PQC algorithm is deprecated or banned in one jurisdiction but used in another, cross-continental DNS interoperability could break down . He asked what the IS3C Dynamic Coalition could do to make this risk explicit and prevent it .
De Natris responded that proactive community-led testing and implementation of PQC solutions may be the best defence against poorly designed regulation, since "focusing on studying, testing and implementing post-quantum cryptography solution may prevent bad regulation" . He acknowledged that the IS3C working groups should explicitly address the fragmentation risk as a topic, and reiterated the importance of bringing diverse stakeholders into the conversation rather than allowing each community to remain in its own silo .
---
#
Future Applications and Constrained Devices
Philippe Foucart of Orange raised a forward-looking question about whether future applications - such as agentic AI running over UDP - might introduce new DNS security requirements, particularly around authenticity and integrity of messages . Müller-Brus acknowledged the concern but noted that it is not currently a primary research focus, largely because the assumption is that PQC validation will occur at recursive resolvers rather than at the device level, meaning constrained devices and future applications would communicate with these resolvers rather than performing validation themselves .
---
#
Conclusions and Call to Action
The session closed with a broad call for cross-stakeholder collaboration, urgency, and coordinated global action. De Natris summarised the challenge: most stakeholders are "looking at somebody else to start the action," which historically leads to collective inaction and mutual blame . He urged all interested parties to join IS3C's working groups and contribute to the coordinated effort . Müller-Brus concluded that DNSSEC is further along than RPKI in its PQC transition, but that neither is ready, and that the technical, governance, and incentive challenges ahead are substantial . Bonis closed with characteristic dry humour, noting that "silos might be very safe for quantum, in particular on the moon" - a wry acknowledgement that isolation is not a viable strategy.
The session's report and related materials were made available on the IS3C website and AFNIC's session page , and the working groups on DNS and RPKI were identified as the primary vehicles for taking the work forward. The overarching message was clear: the window for preparation remains open, but it is narrowing, and the time for coordinated action - technical, political, and institutional - is now.
DNS relies heavily on cryptography, particularly through DNSSEC, which will not resist quantum computing attacks - AFNIC's role is on the affected side, not the quantum computing development side
Arg. 1Pierre Bonis clarifies that AFNIC's interest in post-quantum cryptography is from the perspective of those affected by quantum computing, not those building quantum computers. DNS uses cryptography extensively, most notably through DNSSEC, and the current cryptographic algorithms used will not withstand quantum attacks. AFNIC therefore needs to prepare for the transition to post-quantum-compliant security.
Bonis explicitly stated that the session is about post-quantum cryptography from the side of those affected, not those building quantum computers . He noted that DNS uses cryptography and that DNSSEC is the most well-known application of cryptography in DNS . He further confirmed that current DNSSEC cryptographic algorithms will not resist quantum computing .
on: Current cryptographic algorithms used in DNS and DNSSEC will not withstand quantum computing attacks, necessitating urgent preparation for post-quantum cryptography transition
Post-quantum cryptographic algorithms are larger and slower, potentially creating latency and performance problems for DNS resolution
Arg. 2The post-quantum cryptographic algorithms that would replace current ones are stronger but come with larger key sizes and require more processing time. Since DNS handles an enormous volume of queries in very short timeframes, introducing these heavier algorithms could significantly degrade resolution performance. This makes careful testing and preparation essential before any transition.
Bonis noted that post-quantum algorithms are 'stronger, of course, but longer and they take more time to work' . He highlighted that DNS involves 'a lot of queries in a very, very short time' and that using such algorithms 'may be a problem in terms of latency' and could 'have a huge impact on the performance of the resolution in the DNS' .
on: The global deployment of security-related internet standards, including DNSSEC and RPKI, has been poor, and this must change before the quantum threat becomes acute
Removing DNSSEC would eliminate the post-quantum cryptography problem for DNS but would be a highly undesirable "nuclear option"
Arg. 3Bonis raises the controversial possibility that if no viable post-quantum solution can be found for DNSSEC without severe performance degradation, one extreme response could be to remove DNSSEC altogether. He acknowledges this would be a deeply undesirable outcome but presents it as a logical consequence if the performance challenges prove insurmountable. He frames it as a 'nuclear option' rather than a preferred course of action.
Bonis stated that 'one way of doing it, if there are no solutions... would be to remove DNSSEC' because 'if we remove DNSSEC, we don't have the post-cryptography problem', immediately qualifying this as 'a very bad thing to say' .
on: Whether removing DNSSEC is a legitimate option to consider in response to PQC performance challenges
There is a lack of empirical evidence demonstrating the actual security benefit of DNSSEC deployment, making it harder to justify its continued use under performance pressure
Arg. 4Bonis points out that despite widespread advocacy for DNSSEC, there is a notable absence of studies demonstrating its concrete security benefits in practice. The available literature tends to either advocate for DNSSEC or report deployment statistics, but does not compare actual attack rates in signed versus unsigned zones. This evidentiary gap weakens the case for maintaining DNSSEC if it becomes a performance burden.
Bonis stated he had 'never seen any study on really what has been the effect of the deployment of DNSSEC' , noting that papers either say 'you have to do it' or report deployment percentages without measuring actual security outcomes . He specifically called for data comparing 'men in the middle attacks' in signed versus unsigned zones .
on: Empirical statistics comparing attack rates in DNSSEC-signed versus unsigned zones are urgently needed to justify continued investment in DNSSEC
Statistics comparing attack rates in signed versus unsigned zones are needed to justify the cost and complexity of maintaining DNSSEC
Arg. 5Bonis argues that evidence-based justification for DNSSEC is urgently needed, particularly as the community faces difficult decisions about its future under post-quantum pressures. Without data showing that signed zones experience fewer attacks than unsigned ones, it is difficult to make a compelling case for the continued investment in DNSSEC. He calls for this research to be conducted now, before performance trade-offs force a decision.
Bonis expressed interest in data on 'the reason, for instance, between zones that are signed and zones that are not signed and the number of men in the middle of attack of this kind that we had in the zone that were not signed compared to the one in the zone that were signed' . He also stated that 'every statistic that can show the actual utility, the actual pertinence of DNSSEC is worth doing now' .
on: Empirical statistics comparing attack rates in DNSSEC-signed versus unsigned zones are urgently needed to justify continued investment in DNSSEC
Dynamic Coalitions such as IS3C demonstrate that the IGF can deliver substantive, long-term technical and policy work
Arg. 6Bonis uses his opening remarks to defend the value of IGF Dynamic Coalitions against critics who view the IGF as ineffective. He argues that IS3C in particular exemplifies how Dynamic Coalitions can gather expertise and work on important intersectional topics over the long term. He suggests this model should be highlighted, especially ahead of the next IGF in Nairobi.
Bonis stated that 'Dynamic Coalitions shows the very opposite' of the view that IGF is not delivering, describing them as 'a way of gathering expertise and working in an intersectional... very important topics in the long run' . He noted this work has continued 'for several years' and should be highlighted 'in preparation of the next IGF in Nairobi' .
ICANN was initially dismissive of PQC concerns but has recently shifted to recognising it as a significant problem
Arg. 7Bonis recounts a public discussion at ICANN where, just months prior, ICANN's technical team (Octo) dismissed post-quantum cryptography as a future concern not requiring immediate attention. Within a fortnight, however, ICANN reversed its position and acknowledged it as a significant problem. This shift illustrates the rapidly evolving awareness of the PQC threat even among key internet governance bodies.
Bonis recalled a public discussion at ICANN where 'Octo said, oh, this is not the problem. We will see that later. And 15 days after, they said, oh, this is a huge problem' . He also noted that ICANN is now 'very much concerned' with the key rollover and is beginning to recognise the need to work on post-quantum as well .
on: Proactive community-led action on PQC, including testing and implementation, is preferable to waiting for regulatory intervention
The ability to deploy PQC may depend on access to hardware capable of performing the more demanding mathematical operations required
Arg. 8Bonis argues that the transition to post-quantum cryptography is not solely a software or standards challenge but also a hardware one. The more computationally intensive PQC algorithms will require capable hardware, and access to such hardware may not be equally available to all operators. This introduces a dimension of inequality into the PQC transition that goes beyond the question of which standards to adopt.
Bonis stated the need to 'test the hardware that can help us to do the math quicker' and later elaborated that the fragmentation risk 'might be the question of access to the hardware capacity' , noting it is 'not only about HSM' but about broader hardware availability .
Scarcity of hardware resources, driven partly by AI companies purchasing available capacity, could create inequalities between large and small internet operators
Arg. 9Bonis raises the concern that the hardware needed for post-quantum cryptography may become scarce and expensive, partly because large AI companies are acquiring significant portions of available computing resources. This could create a two-tier system where large registries, telcos, and internet players can afford the necessary hardware while smaller operators cannot. Such inequality could undermine the global transition to PQC.
Bonis warned that 'AI giants are buying everything' and that this 'may, at the end of the day, create a problem between big Internet players, big registries, big telcos, and smaller ones' . He expressed concern that this could lead some operators to 'unsign' their zones if they cannot afford the hardware .
on: A quantum security divide between the Western world and developing regions must be prevented, requiring inclusive global coordination
The fragmentation risk is not only about differing standards but also about unequal access to the hardware needed to implement PQC
Arg. 10In response to the question about geopolitical fragmentation of standards, Bonis reframes the issue: the more pressing concern is not that different countries will adopt incompatible standards, but that some countries or operators will simply lack the hardware capacity to implement PQC at all. This hardware access divide could be more damaging than standards divergence in practice.
Bonis stated that the fragmentation question is 'much bigger than the question of different standards' and is really 'the question of access to the hardware capacity' , pointing to 'scarcity, the price rising up' and AI companies purchasing available hardware as key drivers of this inequality .
on: Coordinated, cross-stakeholder and ideally global action is essential to avoid fragmentation and contradictory rules in the PQC transition
on: How to characterise the fragmentation risk: competing standards versus unequal hardware access
DNSSEC is further along in PQC transition planning than RPKI, but neither is fully ready
Arg. 1Moritz Müller-Brus provides an overview of where DNSSEC and RPKI stand in terms of readiness for post-quantum cryptography transition. While DNSSEC benefits from prior experience with algorithm transitions and community engagement, RPKI is at an earlier stage with less clarity on what changes are needed. Neither protocol is fully prepared for the transition.
Müller-Brus summarised that 'DNSSEC is further than RPKI' but acknowledged that both still have significant work ahead . He noted that for RPKI, 'the picture is not as clear yet' and that the community is 'still just not quite sure yet what actually needs to happen in RPKI to transition to post-contra crypto' .
on: The relative urgency of DNSSEC versus RPKI transition to PQC
RPKI, which secures BGP routing, also needs PQC transition but the community is less focused on it compared to DNSSEC
Arg. 2Müller-Brus explains that RPKI, the infrastructure used to secure BGP routing on the internet, is also vulnerable to quantum computing threats and requires a PQC transition. However, the RPKI community appears to be less engaged with this challenge than the DNSSEC community. He suggests that a first step should be to identify the specific technical problems that need to be addressed in RPKI.
Müller-Brus noted that 'compared to DNSSEC, RPKI or at least the deployment of RPKI is still relatively new' and that developers 'are still more busy with working on and not so much with problems that might appear in the future' . He also highlighted that RPKI 'has never changed an algorithm before' and that procedures for doing so 'still have to be tested' .
Post-quantum algorithms are not drop-in replacements for current ones; they have larger keys and signatures, making transition more complex than previous algorithm changes
Arg. 3Müller-Brus explains that unlike previous algorithm transitions in DNSSEC, post-quantum algorithms cannot simply be substituted for existing ones without significant consequences. Their larger key sizes and signatures mean that the transition will be more disruptive and technically demanding than past changes such as the move from RSA to ECDSA. This complexity makes it even more important to begin preparation early.
Müller-Brus stated that 'post-contra-crypto algorithms are probably not dropped in replacement as they have been with transitioning from RSA to ECDSA' and that 'they have larger keys, larger signatures, or maybe both' . He warned that 'transitioning might take even more time if we do not get all behind this transition' .
on: Current cryptographic algorithms used in DNS and DNSSEC will not withstand quantum computing attacks, necessitating urgent preparation for post-quantum cryptography transition
on: Whether PQC preparedness is primarily a technical challenge or a political and governance challenge
Transitioning algorithms in DNSSEC historically takes at least a decade, as seen with the move from RSA to elliptic curve cryptography
Arg. 4Drawing on historical precedent, Müller-Brus notes that algorithm transitions in DNSSEC are slow processes that can take a decade or more to achieve reasonable deployment levels. The transition from RSA to elliptic curve cryptography serves as a concrete example of this timeline. This historical context underscores the urgency of beginning the PQC transition now.
Müller-Brus stated that 'transitioning to a new algorithm in DNSSEC does take quite some time' and that 'when we start from RSA to elliptic curve cryptography this took at least a decade or so before we got reasonable deployment of this new algorithm' .
on: The global deployment of security-related internet standards, including DNSSEC and RPKI, has been poor, and this must change before the quantum threat becomes acute
There are positive signs: more automation, prior experience with algorithm transitions, and IETF community engagement on PQC for DNSSEC
Arg. 5Despite the challenges, Müller-Brus identifies several encouraging developments in the DNSSEC community's approach to PQC. Increased automation of key management processes, experience gained from previous algorithm transitions, and a growing and IETF community working on the problem all provide grounds for cautious optimism. He also highlights SIDN's own research and test lab as a practical contribution.
Müller-Brus noted that 'today we are better changing algorithms' with 'more automation in place' and that the DNS root 'has rolled its keys at least once' . He also pointed to 'a growing number of participants actively working and presenting' at IETF meetings on making DNSSEC quantum safe . SIDN has created 'a test lab' for assessing the impact of PQC algorithms on DNS zones .
on: Proactive community-led action on PQC, including testing and implementation, is preferable to waiting for regulatory intervention
on: Whether removing DNSSEC is a legitimate option to consider in response to PQC performance challenges
RPKI has never undergone an algorithm change before, and the community is still unclear on what exactly needs to change for PQC transition
Arg. 6Müller-Brus highlights that RPKI faces a unique challenge in that it has no prior experience with algorithm transitions, unlike DNSSEC. The community has not yet clearly identified which components of RPKI need to change and which can remain, making it difficult to plan a transition. He suggests that a structured analysis of RPKI's PQC requirements is an important next step.
Müller-Brus stated that RPKI 'has never changed an algorithm before' and that 'procedures for that... still have to be tested' . He noted that 'we are still just not quite sure yet what actually needs to happen in RPKI to transition to post-contra crypto' and called for identifying 'which are the parts that have to change, which are the parts that have to keep, which are the requirements' .
Constrained devices are less of a concern because validation is expected to occur at recursive resolvers rather than at the device level
Arg. 7In response to Philippe Foucart's question about future applications and constrained devices, Müller-Brus explains that the larger packet sizes associated with PQC algorithms are not a primary concern for end devices. This is because DNS validation is expected to be handled by recursive resolvers, which are better resourced, rather than by constrained devices themselves. As a result, this issue does not currently receive high priority in PQC planning.
Müller-Brus explained that 'the assumption probably is also that validation is taking place at recursive resolvers, and these recursive resolvers will take care of it, and these constrained devices will then talk to these recursion themselves' . He acknowledged this is 'why this topic doesn't have such a high priority, unfortunately' .
The DNS protocol itself may need to be modified to accommodate post-quantum algorithms, adding further complexity and time to the transition
Arg. 8Müller-Brus warns that the transition to PQC in DNSSEC may not be achievable through algorithm substitution alone; the DNS protocol itself may require modification. This adds another layer of complexity and extends the timeline for a successful transition. Combined with the need for incentives and education, this makes the overall challenge considerably more demanding.
Müller-Brus stated that 'we have to wait for an algorithm that is suitable and we might then even have to modify the DNS protocol' and that this 'will also take time' . He also noted the need for 'incentives to deploy these new algorithms' including 'education', 'a feel of urgency', and 'maybe even legislation' .
on: The role of legislation and regulation in driving PQC adoption
The threat is real but not yet immediate; however, standards deployment has a poor track record, so preparation must begin now
Arg. 1Wout de Natris acknowledges that a sufficiently powerful quantum computer does not yet exist, but argues that the poor global track record of deploying security-related internet standards means that preparation cannot be delayed. The time required to achieve widespread deployment of new standards means that work must begin well before the threat becomes acute. He uses this argument to justify IS3C's current focus on PQC.
De Natris noted that 'we still have time to do this, but also we do know that standards deployment is not something which has an extremely good reputation around the world at this moment' . He also pointed out that 'new generation security-related standards like DNSSEC and RPKI... are at best moderately well adopted to downright dismal' .
on: The global deployment of security-related internet standards, including DNSSEC and RPKI, has been poor, and this must change before the quantum threat becomes acute
on: Whether PQC preparedness is primarily a technical challenge or a political and governance challenge
A powerful enough quantum computer would break all current digital encryption simultaneously, yet most stakeholders lack a sense of urgency
Arg. 2De Natris uses a thought experiment — imagining all locks in the world opening simultaneously — to illustrate the catastrophic potential of a sufficiently powerful quantum computer breaking all current encryption. Despite this existential risk to digital security, he observes that most stakeholders do not treat the matter with appropriate urgency. He argues this complacency must be overcome.
De Natris posed the hypothetical: 'what happens when the first powerful enough quantum computer is active?... all of a sudden, everything digital, the encryption is broken and it's accessible' . He later stated that 'there is a lack of urgency' and that 'most are looking at somebody else to start the action' .
on: Whether removing DNSSEC is a legitimate option to consider in response to PQC performance challenges
The first encryption algorithm has already been broken by a quantum computer in limited form, indicating the threat is advancing
Arg. 3De Natris points out that the quantum threat is not purely theoretical: a quantum computer has already broken the first encryption algorithm, albeit in a limited capacity. Each additional quantum bit increases the power of these machines, meaning the threat is actively advancing. This makes the window for preparation shorter than many may assume.
De Natris stated that 'the first encryption algorithm is already broken by a quantum computer, although it's very limited in size' and that 'that quantum bit is added, makes it more powerful' .
Most organisations are waiting for others to act rather than taking initiative, which is a dangerous collective inaction
Arg. 4De Natris identifies a pattern of collective inaction in which organisations across sectors are waiting for someone else to lead on PQC preparedness. This diffusion of responsibility means that no one takes ownership of the problem, and the necessary steps are not taken in time. He argues that this dynamic must be broken through coordinated action.
De Natris observed that 'most are looking at somebody else to start the action and that is usually where everybody blames somebody else in the end' . He also noted that universities told him 'there's nothing we can do at this point because the message was there is no algorithm in theory about deploying it' , illustrating how misunderstanding compounds inaction.
IS3C's primary goal is to achieve massive deployment of security-related internet standards, including PQC standards, globally
Arg. 5De Natris describes IS3C's overarching mission as driving the widespread adoption of security-related internet standards and ICT best practices around the world. He notes that most of these standards remain poorly deployed in many regions, and that PQC standards are a key part of IS3C's current focus. The coalition has produced reports, toolkits, and working groups to advance this goal.
De Natris stated that IS3C's 'main goal is to get security-related internet standards and ICT best practices massively deployed, something most of these standards still are not in many parts of the world' . He noted that IS3C has 'produced four reports and two toolkits on internet standards deployment and policy' with the latest focused on PQC .
IS3C has produced reports and toolkits on internet standards deployment and has established working groups on DNS and RPKI for PQC
Arg. 6De Natris outlines the concrete outputs IS3C has delivered in relation to PQC, including reports, toolkits, webinars, and the establishment of two working groups specifically focused on DNS and RPKI. These working groups have already held their first meetings, demonstrating engagement with the technical challenges of PQC transition. This work positions IS3C as a key coordinating body for the global PQC effort.
De Natris reported that IS3C has 'produced four reports and two toolkits on internet standards deployment and policy' , organised 'four different workshops or webinars' on PQC , and 'started two working groups, one on DNS and one on RPKI, both of which had their first meeting' .
on: The relative urgency of DNSSEC versus RPKI transition to PQC
IS3C lacks structural funding to conduct awareness-raising and training at the scale needed to address the global PQC challenge
Arg. 7Despite IS3C's work on PQC, de Natris acknowledges a significant constraint: the coalition lacks the stable, structural funding needed to scale up its awareness-raising and training programmes. Without adequate funding, IS3C cannot reach the global audience necessary to drive meaningful change in standards deployment. He presents this as a critical gap that needs to be addressed.
De Natris stated that 'IS3C is currently preparing for awareness raising and training programs but lacks the structural funding to make this happen at the right scale' .
A digital security and quantum security divide must be prevented, ensuring that developing regions are not left behind in PQC transition
Arg. 8De Natris argues that the transition to post-quantum cryptography must be a global effort, not one that benefits only the Western world. If developing regions are left behind, a quantum security divide will emerge that mirrors existing digital divides. He frames this as both a security imperative and a matter of global equity.
De Natris stated that 'a digital security and quantum security divide must be prevented' and that 'it cannot be that the western world is taking care of itself while the rest is not' .
on: A quantum security divide between the Western world and developing regions must be prevented, requiring inclusive global coordination
Coordinated, cross-stakeholder action at a global or regional level is essential to avoid contradictory rules, as illustrated by the example of 442 conflicting IoT best practices across 21 jurisdictions
Arg. 9De Natris uses the example of IoT policy fragmentation to illustrate the dangers of uncoordinated national approaches to cybersecurity standards. With 442 sometimes contradictory best practices found across just 21 jurisdictions, industry faces an impossible compliance landscape. He argues that PQC must not follow the same path and that global or regional coordination is essential.
De Natris described how IS3C found '442 best practices that the industry had to adhere to' across '21 jurisdictions', 'of which some were totally contradictory' . He warned that 'if you want to do the same with this post-quantum cryptography and advices around it, then industry can never adopt it if you have in every country a different set of rules' .
on: Coordinated, cross-stakeholder and ideally global action is essential to avoid fragmentation and contradictory rules in the PQC transition
Proactive community-led testing and implementation of PQC solutions may help prevent poorly designed regulation from being imposed
Arg. 10De Natris argues that if the technical community proactively tests and implements PQC solutions, it reduces the risk of regulators stepping in with poorly designed or premature regulation. Regulation typically follows when decision-makers perceive that no one is addressing a problem; demonstrating community engagement can pre-empt this. He frames this as a strategic reason for the community to act now.
De Natris stated that 'focusing on studying, testing and implementing post-quantum cryptography solution may prevent bad regulation' and that 'if as a community... we are in grave danger of having regulation that cannot be a good one because this is still a work in progress' .
on: Proactive community-led action on PQC, including testing and implementation, is preferable to waiting for regulatory intervention
on: The role of legislation and regulation in driving PQC adoption
Audience members demonstrated limited immediate awareness of the practical consequences of a quantum security breach
Arg. 1When asked by de Natris what they would do if all digital encryption were simultaneously broken, audience members gave responses that reflected limited immediate awareness of the practical consequences. One audience member responded simply with 'Family', suggesting their first instinct would be to go to their family rather than address the digital security crisis. This illustrated de Natris's point about the lack of urgency among the general public.
When asked what they would do if all digital encryption were broken, Audience Member 1 responded simply 'Family' , prompting de Natris to note 'You'd go home, right?' .
Audience members demonstrated limited immediate awareness of the practical consequences of a quantum security breach
Arg. 1A second audience member, when asked what they would do if all digital encryption were broken, expressed uncertainty and suggested they would not necessarily view the situation as entirely negative, saying they would stay home. This response further illustrated the gap in public understanding of the severity of a quantum security breach.
Audience Member 2 responded to de Natris's thought experiment by saying 'I'm not sure I would see this as so negative. I would say I would stay home' , demonstrating a lack of appreciation for the catastrophic implications of a quantum security breach.
Audience members demonstrated limited immediate awareness of the practical consequences of a quantum security breach
Arg. 1A third audience member raised the question of energy impacts rather than addressing the security implications directly, asking whether a quantum security breach would also affect energy systems. While this shows some awareness of broader systemic risks, it also reflects a deflection from the core security issue de Natris was raising.
Audience Member 3 asked 'there is a question about energy, would it have an impact on energy as well, what can you do?' , shifting the focus away from the immediate security consequences of a quantum breach.
Audience members demonstrated limited immediate awareness of the practical consequences of a quantum security breach
Arg. 1A fourth audience member responded to de Natris's thought experiment by saying they would call Pierre Bonis for a solution, deflecting responsibility to an expert rather than engaging with the systemic nature of the problem. This humorous response nonetheless underscored de Natris's point that most people look to others to solve the problem rather than taking ownership.
Audience Member 4 responded 'if the phone works I would call Pierre for getting a solution' , illustrating the tendency to defer to others rather than engage directly with the challenge of a quantum security breach.
Statistics comparing attack rates in signed versus unsigned zones are needed to justify the cost and complexity of maintaining DNSSEC
Arg. 1Jimson Olufuye echoes Pierre Bonis's call for empirical data on the effectiveness of DNSSEC, arguing that such statistics are important for justifying continued investment in the protocol. He draws on his own experience of conducting DNSSEC roadshows in Lagos to illustrate the need for concrete evidence to support advocacy efforts. He suggests that ICANN should be asked to provide this data.
Olufuye referenced his experience conducting 'a roadshow in Lagos' and mobilising support for DNSSEC, arguing that advocates 'should have something to show that yes, it's actually quite positive' . He called for statistics on DNSSEC effectiveness, echoing Bonis's earlier point about the gap in evidence .
on: Empirical statistics comparing attack rates in DNSSEC-signed versus unsigned zones are urgently needed to justify continued investment in DNSSEC
ICANN should be asked to provide data on the effectiveness of DNSSEC to support evidence-based decision-making
Arg. 2Olufuye specifically calls on ICANN to produce statistics demonstrating the security benefits of DNSSEC, arguing that this data is essential for evidence-based advocacy and policy-making. He also raises the question of whether ICANN is actively working on post-quantum preparedness, given its responsibility for the root servers and core DNS infrastructure.
Olufuye asked 'shouldn't we ask ICANN to give us that statistics because it's good to know what is going on so that we can really fully justify' DNSSEC deployment . He also questioned whether 'ICANN should be concerned about this post-quantum too because of the root servers and what have you' .
on: A quantum security divide between the Western world and developing regions must be prevented, requiring inclusive global coordination
Speaker 1 echoed the call for ICANN to provide statistics on DNSSEC effectiveness and to engage more actively with PQC preparedness
Arg. 1Speaker 1 reiterated the points made by Jimson Olufuye regarding the need for ICANN to provide empirical data on DNSSEC's security benefits and to take a more role in PQC preparedness. The argument reinforces the broader theme that evidence-based decision-making is essential for justifying continued investment in DNSSEC and for planning the PQC transition.
Speaker 1 repeated the call for statistics on DNSSEC effectiveness, noting the gap between having DNSSEC and knowing 'the effect if we don't have it' , and questioned whether ICANN is working on post-quantum preparedness given its responsibility for root servers .
on: Empirical statistics comparing attack rates in DNSSEC-signed versus unsigned zones are urgently needed to justify continued investment in DNSSEC
Future applications such as agentic AI running over UDP may require authenticity and integrity guarantees from DNS, raising new security requirements
Arg. 1Philippe Foucart raises the question of whether future applications, such as agentic AI systems that may run over UDP, will create new demands for DNS security beyond what current mechanisms provide. He suggests that these applications may require authenticity and integrity guarantees that existing higher-level security mechanisms do not fully address. He frames this as a forward-looking consideration for PQC planning.
Foucart noted that 'there are also other applications which may not provide that level of security, possibly running on UDP, whereby maybe authenticity and integrity of the messages would be required' . He specifically mentioned 'genetic AI' as an example of a future application that might create new DNS security requirements .
Fragmentation of technical standards along geopolitical lines is a real risk, potentially leading to incompatible national or regional PQC standards
Arg. 1Jacques Beglinger raises the concern that geopolitical tensions and the fragmentation of the internet could lead to the emergence of competing national or regional PQC standards. He draws a parallel with broader internet fragmentation trends driven by geopolitics, suggesting that the same forces could produce incompatible cryptographic standards. This would undermine global interoperability and the effectiveness of PQC transition efforts.
Beglinger asked 'how close are we to a fragmentation also of these technical standards' and whether 'we end up in the end with a nation standard, with a western standard, with an African standard, things like that, that some kind of competition of standards as we may come closer to even acerbated competition of systems' .
on: Coordinated, cross-stakeholder and ideally global action is essential to avoid fragmentation and contradictory rules in the PQC transition
on: How to characterise the fragmentation risk: competing standards versus unequal hardware access
Unwise or premature regulation driven by geopolitical competition could fragment internet interoperability if different algorithms are banned or deprecated in different jurisdictions
Arg. 1Peter Koch builds on the fragmentation concern raised by Jacques Beglinger, arguing that geopolitical competition combined with poorly designed regulation could lead to specific PQC algorithms being banned or deprecated in some jurisdictions while being used in others. This would break the interoperability of the DNS across borders, undermining the global internet. He calls on the dynamic coalition to make this risk explicit in its work.
Koch warned that 'urgency that Wout mentioned together with geopolitics and competition in algorithms might lead to fragmentation actually when unwise regulation kicks in' . He gave the example that 'if we have a particular algorithm arising in one place, which is deprecated, say, or banned or something in another place, then obviously that interoperability will not be there' .
on: Coordinated, cross-stakeholder and ideally global action is essential to avoid fragmentation and contradictory rules in the PQC transition
The moderator facilitated the discussion by inviting speakers to address questions from the floor and managing the flow of the session
Arg. 1The moderator played a procedural role in the session, directing questions to appropriate speakers and ensuring that audience contributions were incorporated into the discussion. This included inviting Pierre Bonis to respond to audience questions and managing the transition between speakers. The moderator's role was essential in maintaining the structure and flow of the debate.
The moderator invited Pierre Bonis to respond to audience questions by asking 'So, Pierre, do you want to jump in?' and managed the session's conclusion by thanking all participants .
The session is focused on post-quantum cryptography and its implications for internet infrastructure, not on quantum computing itself
Arg. 1Lucien Castex, in his role as session chair, acknowledges and reinforces Pierre Bonis's clarification that the discussion is about preparing internet infrastructure for the post-quantum era, not about quantum computing development. His humorous expression of disappointment underscores the important distinction between the two topics. This framing helps orient the audience towards the practical, infrastructure-focused nature of the discussion.
After Pierre Bonis's introduction, Castex remarked 'Strong statement. So now I understand the session is not about quantum. I'm a bit disappointed, but well' , acknowledging and reinforcing Bonis's earlier clarification that the session concerns post-quantum cryptography from the perspective of those affected, not those building quantum computers .
on: Current cryptographic algorithms used in DNS and DNSSEC will not withstand quantum computing attacks, necessitating urgent preparation for post-quantum cryptography transition
The IGF Dynamic Coalition IS3C serves as an important multistakeholder coordination mechanism for advancing work on internet security standards including post-quantum cryptography
Arg. 2As session organiser and coordinator, Lucien Castex frames the session as a product of collaboration between AFNIC and the IS3C Dynamic Coalition, highlighting the role of IGF structures in bringing together expertise on critical internet security topics. By introducing speakers from both the registry community and the dynamic coalition, he implicitly argues that multistakeholder cooperation through IGF mechanisms is the appropriate vehicle for addressing PQC challenges.
Castex opened the session by explaining that 'this session is called post quantum preparing the internet for post quantum cryptography, it's organized by AFNIC the French internet and the dynamic coalition on internet standard security and safety IS3C' , and he systematically introduced speakers from both organisations throughout the session .
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
All principal speakers agree that DNSSEC and DNS infrastructure rely on cryptographic algorithms that will not survive quantum computing attacks . Bonis clarified that the session concerns those affected by quantum computing, not those building quantum computers . Müller-Brus confirmed that PQC algorithms are not drop-in replacements and have larger keys and signatures . De Natris acknowledged that 'we still have time to do this, but also we do know that standards deployment is not something which has an extremely good reputation around the world at this moment' . Castex reinforced this framing by acknowledging the session is about post-quantum cryptography's implications for infrastructure .
DNS relies heavily on cryptography, particularly through DNSSEC, which will not resist quantum computing attacks - AFNIC's role is on the affected side, not the quantum computing development side
Post-quantum algorithms are not drop-in replacements for current ones; they have larger keys and signatures, making transition more complex than previous algorithm changes
The threat is real but not yet immediate; however, standards deployment has a poor track record, so preparation must begin now
The session is focused on post-quantum cryptography and its implications for internet infrastructure, not on quantum computing itself
Bonis noted that DNS handles 'a lot of queries in a very, very short time' and that PQC algorithms 'may be a problem in terms of latency' . Müller-Brus confirmed that algorithm transitions in DNSSEC 'took at least a decade or so before we got reasonable deployment' . De Natris stated that 'new generation security-related standards like DNSSEC and RPKI... are at best moderately well adopted to downright dismal' , reinforcing the shared view that the poor deployment track record makes early preparation essential.
Post-quantum cryptographic algorithms are larger and slower, potentially creating latency and performance problems for DNS resolution
Transitioning algorithms in DNSSEC historically takes at least a decade, as seen with the move from RSA to elliptic curve cryptography
The threat is real but not yet immediate; however, standards deployment has a poor track record, so preparation must begin now
Bonis stated he had 'never seen any study on really what has been the effect of the deployment of DNSSEC' and called for data comparing attack rates in signed versus unsigned zones . He later affirmed that 'every statistic that can show the actual utility, the actual pertinence of DNSSEC is worth doing now' . Olufuye echoed this, arguing that advocates 'should have something to show that yes, it's actually quite positive' and asked whether ICANN should be asked to provide such statistics . Speaker 1 reiterated the same point, noting the gap between having DNSSEC and knowing 'the effect if we don't have it' .
There is a lack of empirical evidence demonstrating the actual security benefit of DNSSEC deployment, making it harder to justify its continued use under performance pressure
Statistics comparing attack rates in signed versus unsigned zones are needed to justify the cost and complexity of maintaining DNSSEC
Statistics comparing attack rates in signed versus unsigned zones are needed to justify the cost and complexity of maintaining DNSSEC
ICANN should be asked to provide data on the effectiveness of DNSSEC to support evidence-based decision-making
Speaker 1 echoed the call for ICANN to provide statistics on DNSSEC effectiveness and to engage more actively with PQC preparedness
De Natris warned that with '442 best practices that the industry had to adhere to' across '21 jurisdictions', 'some were totally contradictory' , and that PQC must not follow the same path . Beglinger raised the risk of ending up with 'a nation standard, with a western standard, with an African standard' . Koch warned that 'urgency... together with geopolitics and competition in algorithms might lead to fragmentation actually when unwise regulation kicks in' and that if an algorithm is 'deprecated, say, or banned or something in another place, then obviously that interoperability will not be there' . Bonis reframed the issue as also being about 'access to the hardware capacity' , broadening the fragmentation concern beyond standards alone.
Coordinated, cross-stakeholder action at a global or regional level is essential to avoid contradictory rules, as illustrated by the example of 442 conflicting IoT best practices across 21 jurisdictions
The fragmentation risk is not only about differing standards but also about unequal access to the hardware needed to implement PQC
Unwise or premature regulation driven by geopolitical competition could fragment internet interoperability if different algorithms are banned or deprecated in different jurisdictions
Fragmentation of technical standards along geopolitical lines is a real risk, potentially leading to incompatible national or regional PQC standards
De Natris explicitly stated that 'a digital security and quantum security divide must be prevented' and that 'it cannot be that the western world is taking care of itself while the rest is not' . Bonis raised the concern that AI giants purchasing hardware could 'create a problem between big Internet players, big registries, big telcos, and smaller ones' , with potential knock-on effects for developing-region operators. Olufuye, speaking from an African perspective, implicitly reinforced this by calling for evidence and ICANN engagement to support advocacy in regions like Nigeria .
A digital security and quantum security divide must be prevented, ensuring that developing regions are not left behind in PQC transition
Scarcity of hardware resources, driven partly by AI companies purchasing available capacity, could create inequalities between large and small internet operators
ICANN should be asked to provide data on the effectiveness of DNSSEC to support evidence-based decision-making
De Natris argued that 'focusing on studying, testing and implementing post-quantum cryptography solution may prevent bad regulation' . Müller-Brus highlighted positive signs of community engagement, including 'a growing number of participants actively working and presenting' at IETF meetings and SIDN's own test lab . Bonis noted ICANN's recent shift from dismissal to recognition of PQC as 'a huge problem' , suggesting that community pressure and proactive work can drive institutional change. All three implicitly agree that community action is the preferred path over waiting for regulatory mandates.
Proactive community-led testing and implementation of PQC solutions may help prevent poorly designed regulation from being imposed
There are positive signs: more automation, prior experience with algorithm transitions, and IETF community engagement on PQC for DNSSEC
ICANN was initially dismissive of PQC concerns but has recently shifted to recognising it as a significant problem
Both Bonis and de Natris share the view that the PQC transition risks creating or deepening inequalities, whether through hardware scarcity or lack of funding for awareness and training. Bonis warned that 'AI giants are buying everything' and that this 'may, at the end of the day, create a problem between big Internet players, big registries, big telcos, and smaller ones' . De Natris stated that 'IS3C is currently preparing for awareness raising and training programs but lacks the structural funding to make this happen at the right scale' and that 'a digital security and quantum security divide must be prevented' . Both see inequality of access — whether to hardware or to knowledge — as a central challenge in the PQC transition. Both Bonis and Müller-Brus share a detailed understanding of the technical challenges facing DNSSEC in the PQC transition. Bonis highlighted that PQC algorithms are 'stronger, of course, but longer and they take more time to work' and that DNS involves 'a lot of queries in a very, very short time', potentially causing 'a huge impact on the performance of the resolution in the DNS' . Müller-Brus confirmed that PQC algorithms 'have larger keys, larger signatures, or maybe both' and that 'we might then even have to modify the DNS protocol' . Both agree that the technical complexity of the transition is significant and that performance implications must be carefully managed. Both de Natris and Koch share the view that the combination of inaction and geopolitical pressures creates a dangerous environment for the PQC transition. De Natris observed that 'most are looking at somebody else to start the action and that is usually where everybody blames somebody else in the end' and that 'there is a lack of urgency' . Koch warned that this urgency gap, combined with geopolitics, 'might lead to fragmentation actually when unwise regulation kicks in' . Both agree that the IGF Dynamic Coalition has a role to play in bridging silos and preventing this outcome . Bonis, Olufuye, and Speaker 1 all share the view that ICANN should be more actively engaged in both providing evidence of DNSSEC's effectiveness and preparing for PQC. Bonis stated he had 'never seen any study on really what has been the effect of the deployment of DNSSEC' and called for comparative attack data . Olufuye asked 'shouldn't we ask ICANN to give us that statistics' and questioned whether 'ICANN should be concerned about this post-quantum too because of the root servers' . Speaker 1 reiterated the same gap, noting the difference between having DNSSEC and knowing 'the effect if we don't have it' . All three implicitly call for ICANN to take a more evidence-generating and proactive role. Both de Natris and Müller-Brus share the view that RPKI is significantly less prepared for PQC transition than DNSSEC, and that structured community work is needed to address this gap. De Natris noted that IS3C has 'started two working groups, one on DNS and one on RPKI, both of which had their first meeting' and that 'on the RPKI side, the only thing I heard, our members are not discussing it' . Müller-Brus confirmed that 'compared to DNSSEC, RPKI... the picture is not as clear yet' and that RPKI 'has never changed an algorithm before' . Both agree that identifying RPKI's specific PQC requirements is an urgent next step.
It is somewhat unexpected that Bonis, as CEO of a major registry, openly raised the possibility of removing DNSSEC as a 'nuclear option' if PQC performance challenges prove insurmountable . Rather than provoking strong disagreement, the other speakers implicitly accepted this as a legitimate concern to be avoided through proactive action. De Natris's emphasis on urgency and Müller-Brus's cautious optimism about DNSSEC's readiness can both be read as responses to this concern - agreeing that the scenario must be prevented rather than dismissing it as impossible. The consensus that DNSSEC's value must be empirically demonstrated also reflects a shared acknowledgement that the 'nuclear option' is not entirely off the table if evidence and performance cannot be reconciled.
It is somewhat unexpected that technical experts from registries and research institutions converged on the view that the PQC challenge is primarily a governance and political problem rather than a technical one. De Natris stated explicitly that 'this is not a technical issue... it's all about convincing those with decision power' and that 'if decision-makers decide positively, the technicians will get the training and they will get the funding they need' . Müller-Brus, despite being a researcher, acknowledged the need for 'incentives', 'education', 'a feel of urgency', and 'maybe even legislation' . Bonis similarly framed the challenge in terms of institutional readiness and evidence-based advocacy . This convergence between technical and policy perspectives on the primacy of political will was a notable area of unexpected consensus.
It is somewhat unexpected that speakers from different institutional backgrounds - a registry CEO, a coalition coordinator, a session chair, and a DNS operator - all converged on the view that the IGF Dynamic Coalition model is a genuinely effective vehicle for addressing PQC challenges. Bonis stated that 'Dynamic Coalitions shows the very opposite' of the view that IGF is not delivering . De Natris described IS3C's concrete outputs including four reports, two toolkits, and two working groups . Koch, while raising a concern about fragmentation, implicitly endorsed the coalition's role by asking it to address the issue . Castex framed the entire session as a product of this collaboration . This cross-institutional endorsement of the IGF Dynamic Coalition model as a practical governance tool was a notable area of consensus.
The discussion revealed a strong and broad consensus across speakers on the core challenges and necessary responses to post-quantum cryptography threats to internet infrastructure. All principal speakers agreed that: (1) current DNS cryptographic algorithms will not withstand quantum attacks and transition is necessary ; (2) the poor global track record of standards deployment makes early preparation essential ; (3) empirical evidence of DNSSEC's effectiveness is urgently needed ; (4) coordinated global action is required to prevent fragmentation ; and (5) the challenge is as much political and economic as it is technical . There was also notable agreement on the value of the IGF Dynamic Coalition model as a coordination mechanism and on the risk of a quantum security divide between developed and developing regions . The main areas of nuance rather than disagreement concerned the relative urgency of DNSSEC versus RPKI transition and the specific role of hardware access constraints .
Wout de Natris explicitly argued that PQC preparedness 'is not a technical issue' , framing it instead as a matter of 'convincing those with decision power' and 'political, economic decision-making' . He emphasised that 'if decision-makers decide positively, the technicians will get the training and they will get the funding they need' . By contrast, Moritz Müller-Brus devoted his entire contribution to detailed technical analysis of algorithm suitability, key sizes, protocol modification requirements, and the specific readiness gaps in DNSSEC and RPKI , treating the challenge as fundamentally technical in nature. While neither speaker directly contradicted the other, their framing of the core problem diverged significantly.
The threat is real but not yet immediate; however, standards deployment has a poor track record, so preparation must begin now
Post-quantum algorithms are not drop-in replacements for current ones; they have larger keys and signatures, making transition more complex than previous algorithm changes
Pierre Bonis raised the controversial possibility that if no viable PQC solution can be found without severe performance degradation, removing DNSSEC could be considered, calling it a 'nuclear-bottom option' . He further noted the absence of empirical evidence for DNSSEC's security benefits, implying its value may be harder to defend than assumed . Moritz Müller-Brus, by contrast, expressed cautious optimism about the DNSSEC transition, pointing to automation, prior experience, and community engagement as positive signs , and did not entertain the removal option. Wout de Natris framed the entire discussion around the imperative to secure the digital world, arguing that a 'quantum security divide must be prevented' , which is incompatible with abandoning DNSSEC.
Removing DNSSEC would eliminate the post-quantum cryptography problem for DNS but would be a highly undesirable "nuclear option"
A powerful enough quantum computer would break all current digital encryption simultaneously, yet most stakeholders lack a sense of urgency
There are positive signs: more automation, prior experience with algorithm transitions, and IETF community engagement on PQC for DNSSEC
Jacques Beglinger framed the fragmentation risk in terms of geopolitical competition producing incompatible national or regional PQC standards, asking whether 'we end up in the end with a nation standard, with a western standard, with an African standard' . Pierre Bonis responded by reframing the issue: the more pressing concern is 'much bigger than the question of different standards' and is really 'the question of access to the hardware capacity' . He pointed to AI companies purchasing available hardware and driving up prices as the key driver of inequality , suggesting that hardware access divides could be more damaging than standards divergence in practice.
Fragmentation of technical standards along geopolitical lines is a real risk, potentially leading to incompatible national or regional PQC standards
The fragmentation risk is not only about differing standards but also about unequal access to the hardware needed to implement PQC
Moritz Müller-Brus acknowledged that incentives including 'education', 'a feel of urgency', and 'maybe even legislation' might be needed to drive PQC adoption, but expressed explicit caution about the legislative option: 'I'm a bit more careful with this statement' . Wout de Natris took a more nuanced but distinct position, arguing that proactive community action could pre-empt bad regulation: 'focusing on studying, testing and implementing post-quantum cryptography solution may prevent bad regulation' . He warned that if the community fails to act, 'we are in grave danger of having regulation that cannot be a good one because this is still a work in progress' . Peter Koch further warned that 'unwise regulation' driven by geopolitical urgency 'might lead to fragmentation' , adding another dimension to the regulatory debate.
The DNS protocol itself may need to be modified to accommodate post-quantum algorithms, adding further complexity and time to the transition
Proactive community-led testing and implementation of PQC solutions may help prevent poorly designed regulation from being imposed
Moritz Müller-Brus provided a detailed comparative assessment, concluding that 'DNSSEC is further than RPKI' and that RPKI faces greater uncertainty because it has 'never changed an algorithm before' and the community is 'still just not quite sure yet what actually needs to happen in RPKI to transition to post-contra crypto' . Wout de Natris, however, noted that on the RPKI side, 'the only thing I heard, our members are not discussing it. They're not asking for us to be active' , suggesting an even more concerning lack of engagement than Müller-Brus implied. De Natris expressed surprise that 'there doesn't seem to be an overarching organization at this point in time working on it' , indicating a more alarming assessment of RPKI's preparedness than Müller-Brus's relatively measured technical framing.
DNSSEC is further along in PQC transition planning than RPKI, but neither is fully ready
IS3C has produced reports and toolkits on internet standards deployment and has established working groups on DNS and RPKI for PQC
In a session explicitly dedicated to preparing internet infrastructure for post-quantum cryptography, it was unexpected for the CEO of a major DNS registry to raise the possibility of removing DNSSEC as a response to PQC performance challenges . Bonis acknowledged this was 'a very bad thing to say' but nonetheless presented it as a logical consequence if performance trade-offs prove insurmountable. This implicitly contradicted the session's entire premise and the positions of de Natris, who argued for preventing a 'quantum security divide' , and Müller-Brus, who was working on technical solutions to enable the transition . The suggestion also undermined Bonis's own earlier call for statistics to justify DNSSEC's value , since raising the removal option implies he is genuinely uncertain whether DNSSEC's benefits outweigh its costs.
De Natris used a thought experiment to illustrate the catastrophic potential of a quantum security breach, asking what audience members would do if all digital encryption were simultaneously broken . The responses were unexpectedly casual: one said 'Family' and would go home , another said they would 'stay home' and did not see it as entirely negative , a third deflected to energy concerns , and a fourth joked about calling Pierre Bonis for a solution . This was unexpected in a room of internet governance and technical professionals, and it visibly reinforced de Natris's point about the 'lack of urgency' even among those who should be most aware of the threat. The disconnect between the severity of the risk as framed by de Natris and the audience's nonchalant responses highlighted a genuine awareness gap even within the specialist community.
Bonis recounted that in a public ICANN discussion just months prior, ICANN's technical team (Octo) had stated that PQC 'is not the problem. We will see that later' , only to reverse this position within a fortnight, declaring it 'a huge problem' . This was unexpected given ICANN's central role in DNS governance and its responsibility for the root zone. The rapid reversal suggests that even the most authoritative bodies in internet governance had not adequately assessed the PQC threat until very recently, which is at odds with the session's framing of PQC as a well-understood and pressing challenge requiring coordinated action. This also implicitly contradicted Jimson Olufuye's suggestion that ICANN should be a primary source of guidance and statistics on DNSSEC and PQC preparedness .
The session was characterised by broad consensus on the existence and seriousness of the PQC threat to DNS infrastructure, but significant disagreements emerged on several dimensions: (1) whether the challenge is fundamentally technical or political/governance in nature; (2) whether removing DNSSEC is a legitimate option to consider; (3) how to characterise the fragmentation risk (standards competition versus hardware access inequality); (4) the appropriate role of legislation and regulation; and (5) the relative urgency of DNSSEC versus RPKI transition. The most striking unexpected disagreements were Pierre Bonis's suggestion that DNSSEC removal could be considered , the audience's casual responses to the quantum security thought experiment , and ICANN's recent reversal on PQC urgency . Partial agreements existed on the need for coordinated global action, the importance of empirical data on DNSSEC effectiveness, and the reality of the threat, but speakers diverged on mechanisms, priorities, and the severity of current inaction.
All three main speakers agreed that the PQC threat to DNS infrastructure is real and that preparation must begin now. Bonis confirmed that 'the crypto algorithm that we have currently will not resist quantum' and that testing and preparation are essential . De Natris acknowledged that 'we still have time to do this' but warned that 'standards deployment is not something which has an extremely good reputation around the world' . Müller-Brus agreed on the need to transition but noted that 'it's not as urgent as with for example TLS' . However, they diverged on how urgently to act and through what mechanisms, with Bonis focusing on testing and hardware , de Natris on governance and awareness , and Müller-Brus on technical protocol work .
DNS relies heavily on cryptography, particularly through DNSSEC, which will not resist quantum computing attacks - AFNIC's role is on the affected side, not the quantum computing development side A powerful enough quantum computer would break all current digital encryption simultaneously, yet most stakeholders lack a sense of urgency DNSSEC is further along in PQC transition planning than RPKI, but neither is fully ready
De Natris, Koch, and Beglinger all agreed that fragmentation of PQC standards poses a serious risk to global internet interoperability. De Natris warned that without coordination, 'industry can never adopt it if you have in every country a different set of rules' , citing the example of 442 contradictory IoT best practices across 21 jurisdictions . Beglinger raised the spectre of competing national standards , and Koch warned that 'unwise regulation' could lead to specific algorithms being 'deprecated, say, or banned' in some jurisdictions . However, they differed on the primary driver: Beglinger emphasised geopolitics, Koch emphasised regulatory risk, and de Natris emphasised the need for proactive community coordination to prevent both .
Coordinated, cross-stakeholder action at a global or regional level is essential to avoid contradictory rules, as illustrated by the example of 442 conflicting IoT best practices across 21 jurisdictions Unwise or premature regulation driven by geopolitical competition could fragment internet interoperability if different algorithms are banned or deprecated in different jurisdictions Fragmentation of technical standards along geopolitical lines is a real risk, potentially leading to incompatible national or regional PQC standards
Both Bonis and Olufuye agreed that empirical data on DNSSEC's security benefits is urgently needed. Bonis stated he had 'never seen any study on really what has been the effect of the deployment of DNSSEC' and called for data comparing attack rates in signed versus unsigned zones . Olufuye echoed this, arguing that advocates 'should have something to show that yes, it's actually quite positive' and suggested asking ICANN to provide such statistics . However, they differed slightly in purpose: Bonis sought the data to inform a potential decision about DNSSEC's future viability under PQC pressure , while Olufuye sought it primarily to support advocacy and justify continued investment .
There is a lack of empirical evidence demonstrating the actual security benefit of DNSSEC deployment, making it harder to justify its continued use under performance pressure Statistics comparing attack rates in signed versus unsigned zones are needed to justify the cost and complexity of maintaining DNSSEC
Both de Natris and Müller-Brus agreed that the technical community needs to act more decisively, but they assessed the current state of engagement differently. Müller-Brus was 'slightly positive' about DNSSEC progress, pointing to growing IETF participation and SIDN's test lab , and expressed cautious optimism. De Natris, however, observed a broader 'lack of urgency' and noted that 'most are looking at somebody else to start the action' , including universities that told him there was 'nothing we can do at this point' . Both agreed action is needed, but de Natris was considerably more pessimistic about the current level of engagement.
Most organisations are waiting for others to act rather than taking initiative, which is a dangerous collective inaction There are positive signs: more automation, prior experience with algorithm transitions, and IETF community engagement on PQC for DNSSEC
- Post-quantum cryptography (PQC) is a critical and urgent concern for DNS infrastructure, particularly DNSSEC and RPKI, because current cryptographic algorithms will not withstand attacks from sufficiently powerful quantum computers.
- Post-quantum cryptographic algorithms are larger and slower than current ones, posing significant latency and performance challenges for DNS resolution, which relies on high volumes of queries processed in very short timeframes.
- DNSSEC is further along in PQC transition planning than RPKI, but neither protocol is fully ready for the transition; RPKI has never undergone an algorithm change and the community is less focused on its PQC readiness.
- Algorithm transitions in DNSSEC have historically taken at least a decade, meaning preparation must begin immediately given the advancing quantum threat, even though the threat is not yet fully immediate.
- The first encryption algorithm has already been broken by a quantum computer in limited form, demonstrating that the threat is real and progressing, yet most stakeholders lack a sufficient sense of urgency.
- ICANN was initially dismissive of PQC concerns but has recently shifted to recognising it as a significant problem, particularly in relation to the DNS root and IANA functions.
- Removing DNSSEC entirely would eliminate the PQC problem for DNS but is considered a highly undesirable 'nuclear option' that should only be contemplated if no viable PQC solution can be found.
- There is a notable absence of empirical evidence demonstrating the actual security benefit of DNSSEC deployment, making it difficult to justify its continued use under performance or cost pressure.
- Hardware access and capacity constraints, exacerbated by AI companies purchasing available resources, risk creating inequalities between large and small internet operators in their ability to deploy PQC solutions.
- Geopolitical fragmentation poses a real risk of producing incompatible national or regional PQC standards, which could undermine global internet interoperability.
- Unwise or premature regulation driven by geopolitical competition could fragment internet interoperability if different PQC algorithms are banned or deprecated in different jurisdictions.
- Coordinated, cross-stakeholder action at a global or regional level is essential; the example of 442 conflicting IoT best practices across 21 jurisdictions illustrates the dangers of siloed, uncoordinated policy-making.
- IS3C and the IGF Dynamic Coalition are actively working on PQC preparedness through reports, toolkits, and working groups on DNS and RPKI, but lack the structural funding needed to operate at the required scale.
- A digital security and quantum security divide must be prevented to ensure that developing regions are not left behind in the PQC transition.
- Proactive community-led testing and implementation of PQC solutions may help prevent poorly designed regulation from being imposed on the technical community.
- Future applications such as agentic AI running over UDP may introduce new DNS security requirements, though this is not yet a primary concern given the assumption that recursive resolvers will handle PQC validation.
“Pierre Bonis raises the provocative idea that one potential 'nuclear option' response to post-quantum cryptography challenges in DNS would be to remove DNSSEC entirely, and simultaneously admits he has never seen a study demonstrating the actual measurable impact of DNSSEC deployment — i.e., comparing rates of man-in-the-middle attacks in signed versus unsigned zones.”
“Wout de Natris uses a thought experiment: 'Imagine a situation in which an invention would make all locks in the world open simultaneously.' He then draws a direct parallel to what a sufficiently powerful quantum computer could do to all digital encryption.”
“Wout de Natris argues: 'This is not a technical issue... It's all about convincing those with decision power that they can do this... It is about political, economic decision-making and the will to prevent social harm.' He further notes that security-related standards like DNSSEC and RPKI are 'at best moderately well adopted to downright dismal.'”
“Wout de Natris reveals that across 21 jurisdictions studied, IS3C found 442 best practices for IoT policy, some of which were 'totally contradictory,' and warns that a similar fragmentation in post-quantum cryptography guidance would make it impossible for industry to adopt coherent standards.”
“Jacques Beglinger asks: 'How close are we to a fragmentation also of these technical standards? Will we end up with a nation standard, a western standard, an African standard — some kind of competition of standards as we may come closer to acerbated competition of systems?'”
“Peter Koch warns that 'urgency together with geopolitics and competition in algorithms might lead to fragmentation actually when unwise regulation kicks in,' and specifically raises the risk that if a particular algorithm is deprecated or banned in one jurisdiction but used in another, DNS interoperability across continents could break down.”
“Moritz Müller-Brus notes that transitioning from RSA to elliptic curve cryptography in DNSSEC 'took at least a decade,' and warns that the post-quantum transition may take even longer given that the new algorithms are not drop-in replacements — they have larger keys and signatures — while simultaneously acknowledging that the community is 'better at changing algorithms' today than it was previously.”
What is the actual measurable impact of DNSSEC deployment? Is there statistical evidence comparing the rate of man-in-the-middle attacks in signed versus unsigned zones?
Pierre Bonis noted he had never seen a study quantifying the real-world effect of DNSSEC deployment, only papers advocating for it or reporting adoption percentages. Jimson Olufuye echoed this, suggesting ICANN should be asked to provide such statistics. Without this evidence, it is difficult to justify continued investment in DNSSEC, especially as post-quantum migration costs rise.
Should ICANN be formally asked to produce statistics on the security benefits of DNSSEC to justify its continued deployment?
Olufuye suggested that ICANN, given its central role in DNS governance, should be the body to gather and publish data demonstrating DNSSEC's positive impact, which would help advocates mobilise support in regions such as Africa.
What is the current state of ICANN's preparedness for post-quantum cryptography, particularly regarding the root zone and IANA functions?
Olufuye raised whether ICANN is actively working on post-quantum readiness for root servers. Pierre Bonis confirmed there had been a recent shift in ICANN's position, but the timeline and depth of their preparedness remain unclear and warrant further investigation.
Could the fragmentation of the internet due to geopolitics lead to competing or incompatible post-quantum cryptography standards across different regions or nations?
Beglinger raised the risk of national or regional standards emerging (e.g., a Western standard, an African standard, a Chinese standard). Peter Koch reinforced this by noting that unwise regulation could mandate specific algorithms in one jurisdiction that are banned in another, breaking cross-continental DNS interoperability. This is a critical governance and technical risk that requires coordinated study.
How might access to the hardware capacity needed for post-quantum cryptography (e.g., HSMs) create a divide between large internet players and smaller registries or operators?
Pierre Bonis highlighted that scarcity of hardware, price increases, and AI companies buying up computing resources could disadvantage smaller registries and telcos. This potential 'quantum security divide' needs further research to understand its scale and to develop mitigation strategies.
Which post-quantum cryptography algorithms are actually suitable for use in DNSSEC, and what protocol modifications to DNS might be required to accommodate them?
Moritz noted that it is still unclear which standardised or forthcoming post-quantum algorithms will be suitable for DNSSEC, and that DNS protocol modifications may be necessary. Resolving this is a prerequisite for any deployment roadmap.
What is the impact of post-quantum cryptography algorithms on DNS validation performance, particularly at the recursive resolver level?
Moritz mentioned that SLM has studied the signing side but is now investigating the validation side. Understanding the latency and computational cost of validating post-quantum signatures at scale is essential before any transition can be planned.
What specific changes are required in RPKI to transition to post-quantum cryptography, and which components must change versus which can remain?
Moritz noted that RPKI is less mature than DNSSEC in its post-quantum readiness, that no algorithm change has ever been performed in RPKI, and that the community has not yet clearly identified what needs to change. A structured technical analysis, similar to what has begun for DNSSEC, is needed urgently.
Why is there a lack of urgency within the RPKI community regarding post-quantum cryptography, and what overarching organisation, if any, is coordinating work on this?
Wout expressed surprise that RPKI operators and their representative bodies are not yet actively discussing post-quantum readiness. Identifying the governance gap and finding or creating a coordinating body is an important next step.
How can the risk of fragmented, contradictory national or regional regulations on post-quantum cryptography be prevented, and what role can the IGF Dynamic Coalition IS3C play in coordinating a globally coherent approach?
The discussion of 442 contradictory IoT best practices across 21 jurisdictions was cited as a cautionary tale. Peter Koch explicitly asked what the Dynamic Coalition could do to prevent similar fragmentation in post-quantum standards. This requires a concrete policy coordination strategy.
How will future internet applications running over constrained or UDP-based protocols (e.g., agentic AI applications) be affected by the transition to post-quantum cryptography in DNS, and are current assumptions about recursive resolvers handling validation sufficient?
Foucart raised the concern that emerging applications may have different security requirements for DNS authenticity and integrity, and that the assumption that recursive resolvers will absorb the complexity may not hold for all future use cases. This area was acknowledged but noted as not yet a primary research focus.
What incentive mechanisms (financial, regulatory, educational) will be needed to drive deployment of post-quantum cryptography algorithms in DNSSEC and RPKI once suitable algorithms are standardised?
Moritz noted that financial incentives were used historically to drive DNSSEC adoption and that education and a sense of urgency will also be needed. Wout stressed that decision-makers need to be convinced. Designing effective incentive frameworks is a key area for further work.
How can IS3C secure structural funding to run awareness-raising and training programmes on post-quantum cryptography at the scale needed to prevent a global digital security divide?
Wout explicitly stated that IS3C lacks the structural funding to implement its planned programmes. Without resolving this, the coalition's ability to drive global adoption, particularly in the Global South, will be severely limited.
Is removing DNSSEC a realistic fallback option if post-quantum migration proves technically or economically infeasible, and what would the security consequences be?
Pierre Bonis raised this as a 'nuclear option' that should not be dismissed without evidence. Given the absence of data on DNSSEC's actual security benefits, a rigorous cost-benefit analysis of this scenario is needed to inform future policy decisions.
