We put Diffie-Hellman and ML-KEM side by side on size, latency, compute, and security, and land on the smartest move: a hybrid key exchange that runs both and combines their secrets, so an attacker would have to break both at once.
We zoom in on key exchange and its urgent "harvest now, decrypt later" threat, where attackers record encrypted traffic today to decrypt once quantum hardware matures. Then we meet the two contenders: classical Diffie-Hellman and post-quantum ML-KEM.
Quantum computers will break today's crypto. We introduce the two pillars of a secure handshake, key exchange and auth, and how each faces a different quantum threat: "harvest now, decrypt later" versus the slower risk to long-lived trust anchors.
So far, the industry has been testing post-quantum key exchange and authentication separately in a quest for a quantum-secure future. We recently have been experimenting with TLS and SSH using both post-quantum key exchange and authentication. The