No single participant can reliably check post quantum security in connections
Nothing Breaks: No Single Peer Can Soundly Gate Post-Quantum Delivery
Cryptography and Security
Summary
This paper finds that it is impossible for any one computer or user in a network to fully verify whether a connection is protected against future quantum computers. The post-quantum security depends on a complex relationship between the server's setup and the clients that connect to it, which no single peer can completely monitor. The authors show that even common tools and checks miss cases where post-quantum protections are missing or weakened. Because current systems don't produce any obvious failure when security is downgraded, these losses go unnoticed. They also show that automation tools and human oversight often fail to spot this problem, making it a hidden risk.
post-quantum cryptographyquantum-resistant securitypeer-to-peer networksSSH clientskey exchangesecurity downgradeconfiguration validationsecurity auditinghybrid key exchange
Authors
Yunze Han
Abstract
Post-quantum protection is delivered to a peer, not declared in a file: whether a session is quantum-resistant is a relation between a server's configuration and the clients that reach it. We show that no single peer can soundly gate that relation. Shipped SSH clients are not ordered: two of their post-quantum capability classes are minimal and incomparable, so a check pinned to either misses the other family's withdrawal. A peer taking both fares no better: it falls back and misses both, or, where classical outranks one family, catches just that one. No case flags both. Nothing above the wire carries the relation either. An artifact-side instrument cannot encode it, because a peer population is not one of its inputs; and across seven configurations on two protocols we find that not one of the five scalars deployed auditors expose to automation moves, while unrelated degradation moves the ones that discriminate at all: the auditors do compute the delivered algorithm, and discard it at the interface automation reads. Nothing else catches the loss either, because nothing breaks: removing a hybrid key exchange starts the daemon, validates the configuration, passes the tests and serves the client, and the adversary it defends against does not exist yet, so no functional signal can carry the loss even in principle. We then show that agents make that state reachable at scale, driving a validated downgrade in 40 of 40 episodes from ordinary engineering prose, against 0 of 40 on a matched neutral document.