{
  "id": 12623876,
  "title": "Surfshark claims a major first by bringing full post-quantum security to WireGuard",
  "url": "https://urgent.news/2026/10/07/surfshark-claims-a-major-first-by-bringing-full-post-quantum-security",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T12:21:14.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/vpn/vpn-services/surfshark-claims-a-major-first-by-bringing-full-post-quantum-security-to-wireguard"
  },
  "original_language": "en",
  "account": "Surfshark VPN provider has achieved a major milestone by implementing full post-quantum security in its WireGuard protocol. This accomplishment is significant as it marks the first time full post-quantum security has been achieved in a consumer VPN application.\n\nThe upgrade focuses on server authentication, which is crucial for preventing future session takeovers. Quantum computers, while still sounding like science fiction, have the potential to effortlessly crack today's encryption. Recognizing this threat, Surfshark has taken steps to prepare for the day when quantum computers can be used to compromise VPN security.\n\nSurfshark's latest update secures every pillar of a private connection against future quantum threats. While many tech giants and rival VPNs have integrated basic post-quantum key exchanges, achieving full post-quantum security in the authentication process remains rare. Surfshark's implementation ensures that malicious actors using futuristic quantum technology cannot impersonate VPN servers and hijack user connections.\n\nAuthentication, the often-overlooked third pillar of quantum security, involves verifying the identity of VPN servers. If an attacker uses a quantum computer to break the VPN's authentication layer, they can perform a session takeover, intercepting all data exchanged during the connection. Surfshark has addressed this vulnerability by integrating ML-DSA (digital signature algorithm) certificates for authentication into its WireGuard protocol.\n\nWhile many companies have begun integrating basic post-quantum key exchanges, fully securing the authentication process is a challenge. Small-scale implementation delays often create a vulnerability when quantum computers become accessible. Surfshark has taken a proactive approach by deploying ML-DSA certificates, achieving the first full post-quantum WireGuard implementation.\n\nThis technical milestone builds upon Surfshark's proprietary VPN protocol, Dausos, which was designed with complete post-quantum security from the ground up. While very few consumer applications have adopted ML-DSA, AWS KMS and Google Cloud KMS are among the few cloud key-management services that have implemented it. Surfshark's move sets it apart in the consumer space, providing a level of security rarely seen among major tech platforms.",
  "summary": "Surfshark is stepping up its encryption game, rolling out full post-quantum security for the WireGuard protocol to protect your data from the supercomputers of tomorrow.",
  "key_points": [
    "Surfshark VPN provider implements full post-quantum security in WireGuard protocol.",
    "Upgrade focuses on server authentication to prevent future session takeovers.",
    "ML-DSA digital signature algorithm certificates added for authentication."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}