Preserve circuit-layer confidentiality against a quantum-capable adversary
[Many](https://eprint.iacr.org/2015/008) [researchers](https://eprint.iacr.org/2015/287), ourselves included, have been aiming [for](https://gitweb.torproject.org/torspec.git/tree/proposals/249-large-create-cells.txt) [quite](https://gitweb.torproject.org/torspec.git/tree/proposals/263-ntru-for-pq-handshake.txt) [some](https://gitweb.torproject.org/torspec.git/tree/proposals/269-hybrid-handshake.txt) [time](https://gitweb.torproject.org/torspec.git/tree/proposals/270-newhope-hybrid-handshake.txt) to protect Tor traffic against a hypothetical future adversary who has access to a quantum computer capable of breaking ECDH key exchanges which have occurred in the past and been recorded.
This is the parent ticket for organising the work into smaller, byte-sized chunks and tracking overall progress.
issue