Security1 distinct publisher3 min readPublished
Allot CTO Yaakov Stein sorts operator traffic by how long it stays worth stealing, and puts TLS hybrid key exchange first. The vendor answers he flags as suspicious are all deferrals dressed as prudence.
The Watch · Security desk

build
Hybrid Post-Quantum TLS: Same Protocol, a 1,216-Byte Key Share1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
security
GitLab 19.3 puts agent runtime, inference models and secrets under one permission model1 distinct publisher
security
An agent guard that runs on your laptop, and cannot tell you whether anyone keeps it on1 distinct publisher
Compiled by The WatchSomething wrong?How this is made
Mosca's equation is a shelf-life argument, and Stein uses it as the triage tool [1]. The interesting part is where the buckets land inside a carrier. Subscriber voice, browsing and streaming are worthless within hours [3]. Subscriber identity mappings, billing records and call metadata stay sensitive for years [2]. Some core traffic leaks internal topology, and exposing certain interfaces can damage operator-to-operator relationships [5]. Credit card data in subscriber traffic stays sensitive for years too, but Stein hands that to the browser or the app rather than the network [4]. Anything that can reveal a personal or system password goes to the top [6].
That ordering matters because it decides what a harvest-now-decrypt-later collector actually gets. Traffic with an hours-long lifetime is not worth storing against a future decrypt. Identity mappings and billing records are.
The work order Stein gives is four steps and one deferral. Inventory every use of public-key crypto first: 5G SBA interfaces, IKE for IPsec links, DNSSEC, encrypted APIs [7]. Then move everything on TLS to hybrid key exchange, including SBA, SEPP, web portals and OSS/BSS APIs [8]. Then IPsec: backhaul, inter-DC, LTE roaming [9]. Then remaining public-key protocols, including proprietary ones [10]. Only after key exchange is covered does authentication of long-lived connections come up, because those can absorb the large public keys of the standardized PQC signature schemes [11]. Software authentication of short-lived connections waits [12]. Hardware authentication and attestation wait on vendors [13]. Ordinary subscribers need nothing from the operator, though enterprise and government customers may [14].
If only one deployment lands this year, Stein puts it at hybrid ML-KEM, X25519 with ML-KEM, with crypto-agile fallback to HQC, on TLS-protected SBA and management-plane interfaces [15]. He calls that the single easiest and most impactful measure available [16].
The procurement side is where this gets usable. Worse than "we don't yet support PQC," per Stein, is "we are waiting for the standards to stabilize" [17]. His counter is that not all RFCs are final, but PQC is being standardized faster than any major telecom innovation, and crypto-agility rather than delay is the way to future-proof [18]. The next two answers he flags are "cryptographically relevant quantum computers are still not here" and "our encryption is based on symmetric encryption and so is quantum safe" [19]. He reads both as either misunderstanding or deliberate deception [20]. The second one is checkable in a meeting: 5G subscriber authentication does rest largely on symmetric keys, but the PKI around it does not [21], so a vendor invoking symmetric crypto is describing one layer and being silent about the one that breaks.
Note what the two lists share. All four suspicious sentences are timing arguments rather than capability statements, and the only real test is whether a vendor can produce an artifact to back one up. Ask for the crypto inventory and the hybrid key exchange status on a named TLS interface and the answers become falsifiable, because those are steps one and two of the sequence Stein lays out [7][8]. That is why the inventory is first: it converts vendor assurance into a list you can audit.
Stein also flags an operational failure mode, and it has nothing to do with the math: a missed interface is the likely point of failure [22]. Which is a restatement of the inventory problem. If step one is incomplete, steps two through four inherit the gap and nobody finds it until something outside the inventory is still negotiating a classical-only key exchange.
Ranked by verification strength, evidence, and original report placement.
The second step is migrating everything using TLS, including SBA interfaces, SEPP, web portals and OSS/BSS APIs, to hybrid key exchange, described as the most readily available technology.
Stein says the low-hanging fruit is TLS key exchange: deploying hybrid ML-KEM (X25519 ECC with ML-KEM, and if possible with crypto-agile backup to HQC) on all TLS-protected SBA and management-plane interfaces.
Stein calls hybrid ML-KEM on TLS-protected SBA and management-plane interfaces the single easiest and most impactful PQC measure for any operator.
Traffic shelf-life is one of the terms in Mosca's equation for PQC readiness urgency, and is therefore important to estimate, according to Dr. Yaakov Stein, VP CTO of Allot.
Several types of signaled operator metadata can remain sensitive for years, including subscriber identity mappings, billing records and call metadata.
Subscriber voice calls, web browsing and streaming are worthless within hours.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One named expert, no second reading
Everything traces to a single conversation between Help Net Security and Allot's Yaakov Stein. The specificity is genuine — named interfaces (SBA, SEPP, OSS/BSS APIs), a named algorithm pairing, a named historical breakage — and specificity is what makes an interview worth reading. But no standards document, no operator, no competing engineer is brought in to test the ordering, and the one comparative superlative about standardisation pace is left hanging. This is an expert's checklist, and should be read as one.
A prescription, not a deployment record
No operator anywhere in this reporting is shown having done any of it — not the inventory, not hybrid key exchange on a single SBA interface. The nearest thing to field experience runs the other way: the Kyber client hello that broke middleboxes and had to be pulled, recounted without a date, a network or a name. There is no basis here for scoring uptake.
Advice cooler than its own category
Most of this piece tells operators what to postpone: signatures on short-lived connections, hardware attestation, ordinary subscribers, the whole subscriber payment layer. That is unusual restraint in quantum-security commentary, and there is no product pitch attached. Two lines lean the other way — 'faster than any major innovation in telecom history' and 'the single easiest and most impactful' — rankings nobody has measured. Net, the story asks for less than the field around it does.
The supplier writes the buyer's checklist
Allot sells into exactly the operator security budget this sequence would open, and step one — inventory every interface that touches a public key — is the kind of engagement a vendor in that category is paid to run. Worth noticing what the format allows too: an executive gets to hand buyers a script for interrogating other suppliers, with no supplier present to answer. To the story's credit, no Allot product is named and no rival is either, and the guidance repeatedly tells operators to spend less rather than more.
Clear provenance, untested substance
We know exactly whose judgement this is — named speaker, named employer, stated title, on-the-record answers — and that clean provenance is most of what our read rests on. What we cannot establish from one interview is whether the ordering survives contact with a live core, or whether the traffic buckets match what carriers actually see. Confidence in who is talking; much less in whether it has been tried.