
Surfshark has added post-quantum server authentication to its WireGuard implementation on iOS and macOS, building on the quantum-resistant key exchange protection it introduced earlier this year.
The announced upgrade makes Surfshark’s WireGuard implementation fully post-quantum secure, according to the company. Support for additional platforms is planned.
The development builds on the provider’s January rollout of post-quantum protection for WireGuard, which focused on securing the process used to establish shared encryption keys. The latest addition covers a separate part of the connection: verifying that the VPN server is genuine.
Surfshark is a consumer VPN provider offering encrypted connections, multi-hop routing, and RAM-only servers. The announcement concerns its own WireGuard implementation, not a change to the protocol across all VPN services.
From key exchange to authentication
The earlier upgrade targeted “harvest now, decrypt later” attacks, in which adversaries capture encrypted traffic and retain it until sufficiently powerful quantum computers can break the public-key cryptography used to establish the connection’s encryption keys.
Protecting key exchange addresses that risk, but authentication presents another potential attack surface. If a future quantum-capable attacker could defeat the mechanisms used to verify a server’s identity, they could impersonate that server and interfere with new connections.
Surfshark’s latest update adds ML-DSA, the Module-Lattice-Based Digital Signature Algorithm, to protect authentication. The company says the server creates a digital signature with its private key, and the client can verify it to confirm the server’s authenticity.
This complements ML-KEM, the Module-Lattice-Based Key-Encapsulation Mechanism, which Surfshark identifies as the technology protecting key establishment in its implementation.
The two algorithms serve different purposes: ML-KEM establishes a shared secret to protect traffic, while ML-DSA provides digital signatures for authentication. Together, they address both the risk of later decrypting captured traffic and future attempts to impersonate VPN infrastructure.
Both rely on lattice-based mathematical problems believed to resist attacks from classical and quantum computers. The US National Institute of Standards and Technology finalized ML-KEM and ML-DSA as FIPS 203 and FIPS 204, respectively, in August 2024.
Apple platforms first
Surfshark says its custom Dausos VPN protocol already uses the same combination of post-quantum key establishment and authentication. Dausos is currently available on macOS.
For WireGuard, the newly announced authentication protection is available on macOS and iOS.
Surfshark has not provided a rollout date for the remaining platforms, so January’s broader key-exchange availability should not be taken as confirmation that every app now supports the combined protection.






Leave a Reply