Surfshark Adds ML-DSA Authentication to Post-Quantum WireGuard

Surfshark post-quantum WireGuard
Hub Hub

Insider Brief

  • Surfshark has added ML-DSA-based certificate authentication to its WireGuard implementation, completing its stated full post-quantum security architecture.
  • The company combines ML-DSA authentication with previously added ML-KEM encryption and key exchange to protect VPN traffic against potential quantum attacks.
  • The fully post-quantum WireGuard implementation is currently available on iOS and macOS, with support for additional platforms planned.

PRESS RELEASE — This major security development milestone follows the initial launch of Dausos, Surfshark’s proprietary VPN protocol engineered with complete post-quantum security from the ground up. By pairing encryption with ML-KEM (key encapsulation mechanism) and certificates using ML-DSA (digital signature algorithm) for authentication, WireGuard now incorporates the final step required to deliver complete post-quantum security. Interestingly, this is not even seen among Big Tech companies. Only AWS (Amazon) and Google Cloud KMS have implemented this in their cloud management services, while companies like Apple or Microsoft have not enabled it in their primary user-facing software.

According to Karolis Kaciulis, Leading System Engineer, developing and launching our Dausos protocol with full post-quantum security enabled Surfshark to extend this level of protection across other protocols.

“Developing and launching our Dausos protocol with full post-quantum security paved the way for us to extend this level of protection to WireGuard. Pioneering this allows us to offer users a distinct technological advantage, guaranteeing full post-quantum protection across data traffic, server authentication, and key exchange,” Kaciulis said.

Introducing TQI 2.0Introducing TQI 2.0

What makes Surfshark’s WireGuard protocol fully post-quantum Secure?

Earlier this year, Surfshark announced post-quantum protections for the WireGuard VPN protocol, including post-quantum encryption and key exchange (ML-KEM). Now, the company has gone the extra mile and added the final critical component — certificates using ML-DSA algorithms — required to ensure that all parts are fully protected against post-quantum threats.

“A truly full post-quantum secure VPN rests on three pillars: encryption, key exchange, and authentication. While the industry has widely adopted quantum-safe encryption and key exchange (like ML-KEM), authentication remains the ‘forgotten’ step. Many, including Big Tech, hesitate here because certificates for authentication are difficult to scale and currently lack a global public infrastructure for post-quantum certificates,” Kaciulis explained.

“However, ignoring this last step creates a vulnerability when quantum computers become accessible. Without post-quantum authentication, a quantum computer could simply perform a session takeover, impersonating the server at the very moment you connect. At Surfshark, we took the ML-DSA standards and integrated them with our certificates into a protocol to make the authorization fully quantum-resistant. By using the ML-DSA certificates, we have completed the final pillar, achieving the first full post-quantum WireGuard implementation.”

ML-DSA in Big Tech is in the Early Stages of Development

An evaluation of 15 widely used applications and platforms, like Google, AWS, Cloudflare, and others, assessing their adoption of ML-KEM alongside ML-DSA showed that deployment is currently limited to the simpler ML-KEM post-quantum security transition.

Implementing ML-KEM provides a relatively seamless upgrade, enabling rapid adoption. Conversely, adopting ML-DSA to verify identities means overhauling the shared system of trust behind every secure connection, which helps explain why 8 of the 15 analyzed services have integrated ML-KEM, whereas only 2 have deployed ML-DSA.

The two areas where ML-DSA is currently “deployed” are not consumer applications. They are cloud key-management platforms: Google Cloud KMS and AWS KMS (Amazon). In these services, ML-DSA is provided as an optional signing capability that clients must manually configure and incorporate, rather than being activated by default. Indeed, none of the consumer-facing applications evaluated in the analysis have implemented their authentication mechanisms with certificates using ML-DSA. For example, while Apple offers ML-DSA to application developers and Microsoft has integrated it into Windows, neither company has enabled it within their primary user-facing software, such as Safari, iMessage, Edge, or Microsoft 365.

“It comes as no surprise that industry peers prioritize implementing ML-KEM key exchange before placing authentication on their engineering roadmaps. Although quantum computing poses no immediate threat today, delaying authentication security until these machines emerge leaves connections vulnerable. That is why Surfshark is taking proactive measures to deliver complete post-quantum defense ahead of potential quantum threats,” Kaciulis noted.

Currently, WireGuard with full post-quantum implementation is accessible to iOS and macOS users, with support for additional platforms planned for future releases.

Keep track of everything going on in the Quantum Technology Market. In one place.

Share

Stay Ahead of Quantum

Get the latest research, company news, and market intelligence every week.

More in Research

Related Articles