vendor · quantum risk
Quantum-safe VPN products | Quantum-Safe Claims & Education
Verdict
“Quantum-safe VPN” is a product category claim, not a proof. Demand hybrid/PQ handshake details, versions, and middlebox notes—symmetric AES-256 tunnels alone do not make key exchange post-quantum.
Overview
VPN vendors increasingly market post-quantum or hybrid modes. Educational buyers should separate tunnel ciphers from handshake algorithms.
Cross-read hybrid VPN, WireGuard, and IPsec network pages; use questionnaires for specific products.
Cryptographic profile
- Signatures: IKE/WireGuard/OpenVPN-class handshakes, Optional hybrid KEM modes (vendor-specific)
- Hash: Depends on VPN stack
- Public-key exposure: Remote access concentrates enterprise traffic on gateway crypto.
Claim scrutiny (buyer checklist)
Marketing / stated claims
- Quantum-safe VPN
- Post-quantum VPN
- PQ X25519 hybrid
Open questions
- Which products ship hybrid KEMs in stable releases?
- Client OS support for larger handshakes?
Educational analysis only. Verify primary sources, specs, and audits yourself before any financial or procurement decision.
What breaks
- AES-only marketing for handshakes
- Firmware that cannot upgrade crypto
- No client ecosystem support matrix
Mitigations
- Algorithm-level RFP tables
- Pilot hybrid on admin paths first
- Inventory gateway certificates and identities
FAQ
Is WireGuard quantum-safe?
Standard WireGuard uses classical Curve25519 key agreement—see /is-quantum-proof/wireguard.
Related network pages?
/is-quantum-proof/hybrid-vpn and /is-quantum-proof/vpn
Key concepts (technical dictionary)
Terms used on this page — open a definition: