By Julio Gomez,
Publication Date: 2026-08-10 14:00:00
Welcome to the second half of the journey! In the first five Parts we made sure a future quantum computer can’t decrypt the traffic we send today. Job done? Not quite. Because that leaves a juicy question hanging in the air: when two machines set up a secure channel, how do they know they’re actually talking to who they think they’re talking to?
That’s authentication: the other pillar, and the half almost everyone forgets. It has a genuinely different relationship with the quantum threat, one that catches even seasoned engineers off guard. So pour a coffee, because this is the part I really want you to sit with. No commands yet; we’ll start running them in Part 7.
Authentication is signatures
Authentication is how a peer proves “I am who I say I am.” On the internet, that proof is almost always a digital signature, usually wrapped in an X.509 certificate issued by a Certificate Authority (CA). Your browser trusts a website because a CA signed its…



