A public-interest redesign of website certificates — ready for the quantum era. See how it works →
The problemWhy certificates break trust
The solutionYour keys, checked by many
Who runs itNo single party in charge
Questions & answersShort answers, no jargon
Two clocks are ticking

The internet must fix its trust model and its cryptography — at the same time

Quantum computers will break the signatures that secure the web. The transition forces everyone to touch every certificate anyway. That makes this the one moment when fixing the deeper problem — who gets to speak for your website — costs almost nothing extra.

Clock one

The quantum deadline is earlier than it looks

A sufficiently large quantum computer will break RSA and elliptic-curve cryptography — the mathematics behind every padlock, every digital signature, every certificate on today's internet. Nobody knows the year. Serious governments are planning for the 2030s.

But the deadline isn't "when the machine exists". Adversaries are recording encrypted traffic today to decrypt it later — the strategy known as harvest now, decrypt later. Anything that must stay confidential for ten years is already on the clock.

That's why NIST finalised post-quantum standards in 2024, why browsers are already rolling out post-quantum key exchange, and why the EU's migration roadmaps say: start now.

The catch nobody advertises

Post-quantum signatures are up to 40× larger than today's. Bolted onto the existing certificate system, they make every website connection noticeably heavier — extra data, on every visit, for every user. ConsensusPKI avoids this by moving the heavy signatures off the connection entirely: they're checked once per hour, not once per visit, and a fully post-quantum proof stays no larger than today's certificates.

Clock two

The trust model keeps failing in the same way

Every few years, the single-point-of-failure design produces the same headline with a different name on it.

2011 — DigiNotar

A breached Dutch authority issued 500+ fake certificates, used to intercept an estimated 300,000 people's communications. The authority went bankrupt; the design survived.

2015–2017 — Symantec

One of the world's largest certificate authorities was found to have mis-issued thousands of certificates over years. Browsers eventually distrusted it entirely — a multi-year, ecosystem-wide cleanup.

Ongoing — the quiet cases

Mis-issuance incidents surface routinely in the transparency logs: wrong domains, skipped checks, compromised registrars. Each one is accepted by every browser until noticed and revoked.

Transparency logging made these visible. It didn't make them impossible. The certificates all worked.

Why fix both at once

The migration is the opportunity

Everything gets touched anyway

The post-quantum transition forces new keys, new certificates and new software on every website and browser. A once-in-a-generation upgrade window is open.

Retrofits pay forever

Bolting big signatures onto the old design taxes every connection, for every user, indefinitely. Redesigning what travels per connection removes the tax once, permanently.

Trust must be rebuilt regardless

New algorithms mean re-establishing every trust relationship anyway. That's exactly the moment to stop rebuilding single points of failure.