Niekto po ceste zaznamená zašifrovanú komunikáciu. Prečítať ju zatiaľ nevie — a ani nemusí.
Šifrovanie, ktoré počíta aj s kvantovými počítačmi.
Post-kvantové šifrovanie je nová generácia šifrovania, navrhnutá tak, aby odolala nielen dnešným počítačom, ale aj budúcim kvantovým. Pri Veredare je východisko jednoduché: tvoja pošta cez nás nejde vôbec. To málo, čo cez náš server ide — profil s nastaveniami —, sa zašifruje ešte v tvojom zariadení a od verzie 0.18.0 ide k serveru výhradne post-kvantovým spojením.
Stav k 24. 9. 2026 · English below
Ulož teraz, dešifruj neskôr.
Kvantový počítač, ktorý by prelomil dnešné šifrovanie, zatiaľ neexistuje. Hrozba však začína už dnes:
Záznam leží na disku. Heslá, zmluvy a osobné údaje sú dôverné aj o päť či desať rokov.
Dostatočne výkonný kvantový počítač by klasickú výmenu kľúčov (RSA, eliptické krivky) prelomil a záznam spätne rozšifroval. Post-kvantová výmena je navrhnutá tak, aby to nedokázal ani on.
Preto s tým počítajú aj úrady: americký NIST navrhuje klasické asymetrické šifrovanie (RSA, ECC) okolo roku 2030 označiť za zastarané a okolo roku 2035 zakázať. Európska únia v koordinovanej roadmape z júna 2025 odporúča začať s prechodom do konca roka 2026 a kritické systémy prejsť do roku 2030.
Čo presne máme pri Veredare
Pošta cez nás nejde
Veredar hovorí s tvojím poštovým serverom priamo. Na našich serveroch nie je z tvojej pošty čo zaznamenať ani uložiť.
Profil šifrovaný v zariadení
Ak zapneš synchronizáciu, profil sa zašifruje AES-256-GCM kľúčom z tvojej frázy ešte v zariadení a na server ide len šifra. Symetrické 256-bitové šifrovanie sa považuje za odolné aj voči kvantovým počítačom: Groverov algoritmus ho oslabí zhruba na úroveň 128 bitov.
Synchronizácia, aktualizácie, Modulo
Od verzie 0.18.0 (24. 9. 2026) sa Veredar k synchronizačnému serveru, k aktualizáciám a k Modulu pripojí výhradne s post-kvantovou výmenou kľúčov. Server, ktorý ju nepodporuje, odmietne — žiadny tichý ústup na slabšie šifrovanie.
Pošta, kalendáre a kontakty
Pri pošte (IMAP, SMTP) a pri CalDAV a CardDAV (iCloud, Fastmail, Nextcloud…) Veredar od verzie 0.18.0 na počítači post-kvantovú výmenu uprednostní — Gmail ju už vie. Ak ju server nepozná, pripojí sa klasicky; o tom rozhoduje server. Ako je šifrované ktoré spojenie, ukážu Nastavenia → Zabezpečenie.
Adresy, na ktorých sme 24. 9. 2026 overili, že server dohodne post-kvantovú výmenu kľúčov X25519MLKEM768. Moderný prehliadač — Chrome a Edge na počítači od verzie 131, Firefox na počítači od 132, Safari od iOS a macOS 26 — ju použije sám; starší sa pripojí šifrovane ako doteraz, len bez post-kvantovej časti. Ktoré prehliadače ťa chránia →
- veredar.com
- sync.veredar.com
Prečo je to výhoda
Čo neprechádza cez náš server, to sa u nás nedá ani zaznamenať — a tvoj profil ide von len zašifrovaný kľúčom, ktorý máš ty. Firmy bez post-kvantovej ochrany dnes posielajú dáta, ktoré si niekto môže uložiť a prečítať neskôr, a prechod ich ešte len čaká. Tu je ten prechod na strane našich serverov hotový a nemusíš nič nastavovať.
Čo post-kvantové zatiaľ nie je
- Pošta. IMAP a SMTP idú cez šifrovanie systému zariadenia k tvojmu poštovému serveru — Gmail, Microsoft 365, Websupport či vlastný. Post-kvantovú ochranu pošty netvrdíme: na zariadeniach Apple ju systém dnes nepodporuje a rozhoduje aj poštový server.
- Certifikáty webov. Certifikačné autority post-kvantové certifikáty zatiaľ nevydávajú. Certifikát overuje identitu servera len v okamihu pripojenia, na „ulož teraz, dešifruj neskôr“ nemá vplyv.
- Podpisy aplikácie. Inštalačné balíky Veredaru sú podpísané klasickým podpisom.
- Staršie verzie. Výhradne post-kvantové spojenia má Veredar od verzie 0.18.0 (24. 9. 2026); staršie verzie sa pripájajú šifrovane klasicky. Aktualizácia sa ponúkne sama.
Otázky
Je moja pošta post-kvantovo chránená?
To netvrdíme. Pošta ide z tvojho poštového servera priamo do zariadenia a cez naše servery nejde vôbec; šifruje ju systém zariadenia a tvoj poštový server. Post-kvantové je to, čo ide cez nás: synchronizácia, aktualizácie a spojenie s Modulom.
Musím niečo nastaviť?
Nie. Stačí aktualizovať na verziu 0.18.0 alebo novšiu, post-kvantové spojenie si Veredar vynúti sám. Profil sa šifruje v zariadení vždy, keď je synchronizácia zapnutá.
Je to teda neprelomiteľné?
Nie, a tak to ani nenazývame. Spojenie je chránené aj proti hrozbe, s ktorou klasické šifrovanie nepočíta. Preto hybrid: klasická a nová metóda naraz, aby ak sa jedna ukáže slabá, chránila druhá.
Ako si to overím sám?
Najjednoduchšie hore na tejto stránke: ak sa tvoj prehliadač dohodol na post-kvantovom šifrovaní, uvidíš zelený odznak. Ručne: otvor veredar.com/cdn-cgi/trace — riadok kex=X25519MLKEM768 znamená, že tvoje spojenie práve beží post-kvantovo. Ktoré prehliadače to vedia a od akej verzie, je na stránke Ktoré prehliadače ťa chránia.
Pre IT: technické detaily
- Výmena kľúčov v TLS 1.3 (veredar.com, sync.veredar.com): X25519MLKEM768 = klasická X25519 + ML-KEM-768 (NIST FIPS 203, august 2024), cez Cloudflare.
- Aplikácia (od 0.18.0): synchronizácia, aktualizácie (veredar.com aj inštalačné balíky) a Modulo len TLS 1.3 s jedinou skupinou X25519MLKEM768, bez ústupu — server bez ML-KEM (skúšané na github.com) odmietne. CalDAV/CardDAV a IMAP: X25519MLKEM768 uprednostnená, s ústupom (rustls, certifikát overuje systém). SMTP: X25519MLKEM768, pri serveri bez ML-KEM systémové TLS. Android: pošta cez systémové TLS.
- Profil pri synchronizácii: AES-256-GCM v zariadení, kľúč odvodený z frázy; server ukladá len šifru.
- Overenie (curl s OpenSSL 3.5+): curl -s https://sync.veredar.com/cdn-cgi/trace | grep kex
Stav k 24. 9. 2026. Keď pribudne ďalšia časť, doplníme ju sem s dátumom. Prehľad za celú rodinu apiek: modulocms.sk/bezpecnost.
Encryption that accounts for quantum computers too.
Post-quantum encryption is a new generation of encryption, designed to withstand not only today’s computers but future quantum ones as well. With Veredar the starting point is simple: your mail does not pass through us at all. The little that does go through our server — your settings profile — is encrypted on your device first, and from version 0.18.0 it goes to the server over a post-quantum connection only.
As of 24 September 2026
Harvest now, decrypt later.
A quantum computer able to break today’s encryption does not exist yet. The threat, however, starts today:
Someone on the way records encrypted traffic. They cannot read it yet — and they do not need to.
The recording sits on a disk. Passwords, contracts and personal data stay sensitive for five or ten years.
A powerful enough quantum computer would break the classic key exchange (RSA, elliptic curves) and decrypt the recording after the fact. A post-quantum exchange is designed so that even it cannot.
That is why regulators are planning for it: the US NIST proposes to deprecate classic asymmetric cryptography (RSA, ECC) around 2030 and disallow it around 2035. The European Union’s coordinated roadmap of June 2025 recommends starting the transition by the end of 2026 and moving critical systems by 2030.
What exactly Veredar has
Your mail does not pass through us
Veredar talks to your mail server directly. There is nothing of your mail on our servers to record or store.
Profile encrypted on the device
If you turn on sync, the profile is encrypted with AES-256-GCM on your device, with a key from your passphrase, and only ciphertext goes to the server. 256-bit symmetric encryption is considered resistant to quantum computers too: Grover’s algorithm reduces it to roughly 128-bit strength.
Sync, updates, Modulo
From version 0.18.0 (24 September 2026), Veredar connects to the sync server, to updates and to Modulo with a post-quantum key exchange only. A server that does not support it is refused — no silent fallback to weaker encryption.
Mail, calendars and contacts
For mail (IMAP, SMTP) and for CalDAV and CardDAV (iCloud, Fastmail, Nextcloud…), Veredar prefers the post-quantum exchange from version 0.18.0 on desktop — Gmail already supports it. If the server does not know it, it connects the classic way; that is the server’s decision. Settings → Security shows how each connection is encrypted.
Addresses where we verified on 24 September 2026 that the server negotiates the X25519MLKEM768 post-quantum key exchange. A modern browser — Chrome and Edge on desktop from version 131, Firefox on desktop from 132, Safari from iOS and macOS 26 — uses it on its own; an older one still connects encrypted as before, just without the post-quantum part. Which browsers protect you →
- veredar.com
- sync.veredar.com
Why it is an advantage
What does not pass through our server cannot be recorded there — and your profile only leaves your device encrypted with a key you hold. Companies without post-quantum protection send data today that someone can store and read later, and the transition is still ahead of them. Here it is done on our servers’ side, with nothing for you to set up.
What is not post-quantum yet
- Mail. IMAP and SMTP go through the device’s system encryption to your mail server — Gmail, Microsoft 365 or your own. We do not claim post-quantum protection for mail: on Apple devices the system does not support it today, and the mail server has a say too.
- Website certificates. Certificate authorities do not issue post-quantum certificates yet. A certificate only proves the server’s identity at the moment of connecting; it has no bearing on “harvest now, decrypt later”.
- App signatures. Veredar installation packages are signed with a classic signature.
- Older versions. Veredar has post-quantum-only connections from version 0.18.0 (24 September 2026); older versions connect with classic encryption. The update is offered automatically.
Questions
Is my mail protected post-quantum?
We do not claim that. Mail goes from your mail server straight to your device and never passes through our servers; it is encrypted by the device’s system and your mail server. What goes through us is post-quantum: sync, updates and the Modulo link.
Do I have to set anything up?
No. Update to version 0.18.0 or newer and Veredar enforces the post-quantum connection on its own. The profile is always encrypted on the device when sync is on.
So is it unbreakable?
No, and we do not call it that. The connection is also protected against a threat that classic encryption does not account for. Hence the hybrid: the classic and the new method together, so if one turns out weak, the other still protects.
How can I check it myself?
The easiest way is at the top of this section: if your browser negotiated post-quantum encryption, you will see a green badge. By hand: open veredar.com/cdn-cgi/trace — the line kex=X25519MLKEM768 means your connection is running post-quantum right now. Which browsers support it and since which version is on the page Which browsers protect you.
For IT: technical details
- Key exchange in TLS 1.3 (veredar.com, sync.veredar.com): X25519MLKEM768 = classic X25519 + ML-KEM-768 (NIST FIPS 203, August 2024), via Cloudflare.
- App (from 0.18.0): sync, updates (veredar.com and installer packages) and Modulo use TLS 1.3 with X25519MLKEM768 as the only group, no fallback — a server without ML-KEM (tested against github.com) is refused. CalDAV/CardDAV and IMAP: X25519MLKEM768 preferred, with fallback (rustls, certificate verified by the OS). SMTP: X25519MLKEM768, system TLS for servers without ML-KEM. Android: mail over system TLS.
- Profile sync: AES-256-GCM on the device, key derived from the passphrase; the server stores ciphertext only.
- Check (curl with OpenSSL 3.5+): curl -s https://sync.veredar.com/cdn-cgi/trace | grep kex
As of 24 September 2026. When another part is added, we will list it here with a date. Overview for the whole family of apps: modulocms.com/security.