Windscribe becomes the latest VPN to support post-quantum encryption – here's what you need to know
The provider says the "quantum threat is looming"
Here at Tom’s Guide our expert editors are committed to bringing you the best news, reviews and guides to help you stay informed and ahead of the curve!
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Daily (Mon-Sun)
Tom's Guide Daily
Sign up to get the latest updates on all of your favorite content! From cutting-edge tech news and the hottest streaming buzz to unbeatable deals on the best products and in-depth reviews, we’ve got you covered.
Weekly on Thursday
Tom's AI Guide
Be AI savvy with your weekly newsletter summing up all the biggest AI news you need to know. Plus, analysis from our AI editor and tips on how to use the latest AI tools!
Weekly on Friday
Tom's iGuide
Unlock the vast world of Apple news straight to your inbox. With coverage on everything from exciting product launches to essential software updates, this is your go-to source for the latest updates on all the best Apple content.
Weekly on Monday
Tom's Streaming Guide
Our weekly newsletter is expertly crafted to immerse you in the world of streaming. Stay updated on the latest releases and our top recommendations across your favorite streaming platforms.
Join the club
Get full access to premium articles, exclusive features and a growing list of member rewards.
Windscribe has become the latest VPN to introduce support for post-quantum encryption (PQE), the new industry standard.
Not all providers in our best VPNs list have adopted post-quantum encryption – NordVPN and ExpressVPN are the only two currently supporting it out of our top five.
Windscribe has said it has built PQE into its WireGuard offering, utilising a pre-shared key. The new encryption standard is available on Windscribe's desktop, iOS, and Android VPN apps.
Quantum computers aren't yet widely available. However, security and privacy providers are taking steps to protect users before Q-Day arrives – the point when quantum computers can break most encryption methods.
There is debate about when VPN providers should implement PQE but Windscribe is one the services adopting it sooner rather than later.
Making use of a pre-shared key
Windscribe is post-quantum resistant thanks to utilising a pre-shared key (PSK) and "a post-quantum-resistant encryption algorithm." PSKs are securely shared before needing to be used.
Traditional encryption methods scramble information and can only be read by those with a decryption key. Quantum computers can "evaluate multiple states simultaneously," instead of one-by-one.
This makes Windscribe's regular encryption method vulnerable to attack.
WireGuard's known limitations state it isn't quantum secure by default, but a PSK can be used to "add a layer of post-quantum secrecy."
It later states "the best bet for post-quantum security is to run a truly post-quantum handshake on top of WireGuard, and then insert that key into WireGuard's pre-shared key slot."
Windscribe has made use of PSKs since it introduced WireGuard, but key exchange took place using classical encryption methods.
PSKs are now shared using a PQE algorithm – "TLS 1.3 using the hybrid key exchange mechanism X25519MLKEM768." Windscribe says the PSK is "rotated" each time you log into the app.
How to enable PQE on Windscribe
Windscribe has said its apps "now support post-quantum WireGuard out of the box," starting with the following versions: Desktop 2.17.9, Android 3.93.1835, and iOS 3.9.4.
To make sure PQE is enabled, log out of your Windscribe app and log back in again. This only needs to be done once on each device running Windscribe, and the provider said it is a "must."
Then select the WireGuard protocol, choose your server, and connect.
Windscribe confirmed that its WireGuard protocol remains largely the same. The only difference being the PSK is negotiated using PQE. There isn't an option, or a need, to return to the old WireGuard encryption methods.
PQE is available for both Windscribe Pro and Windscribe Free users, as long as the device supports modern cryptography. Any old devices that don't support it will default back to non-quantum encryption algorithms.
We test and review VPN services in the context of legal recreational uses. For example: 1. Accessing a service from another country (subject to the terms and conditions of that service). 2. Protecting your online security and strengthening your online privacy when abroad. We do not support or condone the illegal or malicious use of VPN services. Consuming pirated content that is paid-for is neither endorsed nor approved by Future Publishing.

George is a Staff Writer at Tom's Guide, covering VPN, privacy, and cybersecurity news. He is especially interested in digital rights and censorship, and its interplay with politics. Outside of work, George is passionate about music, Star Wars, and Karate.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.
