[{"data":1,"prerenderedAt":1371},["ShallowReactive",2],{"{\"cv\":1786552317925,\"version\":\"published\"}widgets\u002Fnavigation-bar":3,"{\"cv\":1786552317925,\"resolve_relations\":[\"ResourceFeatureCard.resource\"],\"version\":\"published\"}\u002Fblog\u002Fsecuring-gitlab-from-xss-and-account-takeover-attacks":66},{"data":4,"headers":45},{"story":5,"cv":42,"rels":43,"links":44},{"name":6,"created_at":7,"published_at":8,"updated_at":9,"id":10,"uuid":11,"content":12,"slug":32,"full_slug":33,"sort_by_date":22,"position":34,"tag_list":35,"is_startpage":15,"parent_id":36,"meta_data":22,"group_id":37,"first_published_at":38,"release_id":22,"lang":39,"path":40,"alternates":41,"default_full_slug":22,"translated_slugs":22},"Navigation Bar","2026-08-05T05:55:49.585Z","2026-08-07T15:41:09.255Z","2026-08-07T15:41:09.269Z",205700094329908,"be34732b-2155-45e7-8ee2-86e1157a8cb4",{"_uid":13,"component":14,"showMarketingBanner":15,"marketingBannerContent":16},"e7a8d72d-8af8-452e-87b2-de4098162fb9","NavigationBar",false,{"type":17,"content":18},"doc",[19],{"type":20,"attrs":21,"content":23},"paragraph",{"textAlign":22},null,[24],{"text":25,"type":26,"marks":27},"See us at Black Hat booth #7505","text",[28],{"type":29,"attrs":30},"textStyle",{"color":31},"#000000","navigation-bar","widgets\u002Fnavigation-bar",0,[],205696803161001,"e116d2fb-7cac-4697-9dcb-91d9283aecc3","2026-08-05T06:19:33.200Z","default","\u002F",[],1786551603,[],[],{"cache-control":46,"connection":47,"content-length":48,"content-type":49,"date":50,"etag":51,"referrer-policy":52,"sb-be-version":53,"server":54,"vary":55,"via":56,"x-amz-cf-id":57,"x-amz-cf-pop":58,"x-cache":59,"x-content-type-options":60,"x-frame-options":61,"x-permitted-cross-domain-policies":62,"x-request-id":63,"x-runtime":64,"x-xss-protection":65},"max-age=0, public, s-maxage=604800, stale-if-error=3600","keep-alive","986","application\u002Fjson; charset=utf-8","Wed, 12 Aug 2026 16:32:27 GMT","W\u002F\"5c1166e3d4b6a105ebbda45ba4aa4e70\"","strict-origin-when-cross-origin","5.941.0","nginx\u002F1.29.1","Origin","1.1 bf30f50cfbcc4e619604398d6a02d0c6.cloudfront.net (CloudFront)","BxS1-t-mt55vovN5i_D80UGCjlCDOVoWo76cWplGCqmsNDlPxxL_hA==","CMH68-P7","Miss from cloudfront","nosniff","SAMEORIGIN","none","0e5e5ccd-b8e3-4878-ae43-1cf015dee002","0.023397","0",{"data":67,"headers":1361},{"story":68,"cv":42,"rels":915,"links":1360},{"name":69,"created_at":70,"published_at":71,"updated_at":72,"id":73,"uuid":74,"content":75,"slug":907,"full_slug":908,"sort_by_date":909,"position":910,"tag_list":911,"is_startpage":15,"parent_id":898,"meta_data":22,"group_id":912,"first_published_at":913,"release_id":22,"lang":39,"path":22,"alternates":914,"default_full_slug":22,"translated_slugs":22},"Securing GitLab from XSS and Account Takeover Attacks","2026-06-15T21:47:33.764Z","2026-07-27T21:13:04.909Z","2026-07-27T21:13:04.924Z",187885378635281,"d6d0d2ae-27e3-4712-b5d0-10444d46d481",{"Tags":76,"_uid":77,"body":78,"title":79,"content":80,"component":325,"seoOgImage":326,"keyTakeaways":331,"previewImage":356,"previewTitle":79,"relatedContent":358,"seoDescription":905,"previewDescription":906},"","69a52ed9-008b-4441-a3c4-57b32d15254b",[],"Securing GitLab from XSS and account takeover attacks",{"type":17,"content":81},[82,140,148,156,168,176,186,194,202,211,219,267,274,308,317],{"type":20,"attrs":83,"content":84},{"textAlign":22},[85,91,103,105,110,119,120,125,134,135],{"text":86,"type":26,"marks":87},"Recent security concerns surrounding GitLab’s ",[88],{"type":29,"attrs":89},{"color":90},"#003B5C",{"text":92,"type":26,"marks":93},"CVE-2024–4835",[94,99,101],{"type":95,"attrs":96},"link",{"href":97,"uuid":22,"anchor":22,"target":22,"linktype":98},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-4835","url",{"type":29,"attrs":100},{"color":76},{"type":102},"underline",{"text":104,"type":26}," ",{"text":106,"type":26,"marks":107},"and ",[108],{"type":29,"attrs":109},{"color":90},{"text":111,"type":26,"marks":112},"CVE-2023–7028",[113,116,118],{"type":95,"attrs":114},{"href":115,"uuid":22,"anchor":22,"target":22,"linktype":98},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-7028",{"type":29,"attrs":117},{"color":76},{"type":102},{"text":104,"type":26},{"text":121,"type":26,"marks":122},"vulnerabilities highlight the ever-present threat of ",[123],{"type":29,"attrs":124},{"color":90},{"text":126,"type":26,"marks":127},"Cross-Site Scripting (XSS)",[128,131,133],{"type":95,"attrs":129},{"href":130,"uuid":22,"anchor":22,"target":22,"linktype":98},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FCross-site_scripting",{"type":29,"attrs":132},{"color":76},{"type":102},{"text":104,"type":26},{"text":136,"type":26,"marks":137},"and account takeover attacks.",[138],{"type":29,"attrs":139},{"color":90},{"type":20,"attrs":141,"content":142},{"textAlign":22},[143],{"text":144,"type":26,"marks":145},"Gitlab’s XSS vulnerability allows attackers to inject malicious scripts into legitimate web pages, potentially stealing ssensitive user or corporate data, and the account takeover vulnerability would allow a cybercriminal to assume control of a GitLab user’s account and commit malware into otherwise legitimate repositories or steal sensitive intellectual property.",[146],{"type":29,"attrs":147},{"color":90},{"type":20,"attrs":149,"content":150},{"textAlign":22},[151],{"text":152,"type":26,"marks":153},"While patching vulnerable software remains a crucial security practice, innovative solutions like Terniion offer an additional layer of protection that defeats both of these attack vectors and renders these CVEs harmless. Let’s explore how Terniion approaches GitLab security and how it can benefit developers.",[154],{"type":29,"attrs":155},{"color":90},{"type":157,"attrs":158,"content":160},"heading",{"level":159,"textAlign":22},2,[161],{"text":162,"type":26,"marks":163},"Understanding the Threat",[164,166],{"type":29,"attrs":165},{"color":90},{"type":167},"bold",{"type":20,"attrs":169,"content":170},{"textAlign":22},[171],{"text":172,"type":26,"marks":173},"Fundamentally, for the XSS, account takeover, or many other classes of vulnerabilities to be exploited, the GitLab server must be reachable by an outside attacker. Traditionally, servers must have public IPs and be reachable for normal, authorized use by approved users. Unfortunately, opening ports for legitimate usage also opens up channels that can be abused by attackers.",[174],{"type":29,"attrs":175},{"color":90},{"type":157,"attrs":177,"content":179},{"level":178,"textAlign":22},3,[180],{"text":181,"type":26,"marks":182},"Traditional Security vs. Proactive Defense",[183,185],{"type":29,"attrs":184},{"color":90},{"type":167},{"type":20,"attrs":187,"content":188},{"textAlign":22},[189],{"text":190,"type":26,"marks":191},"Traditional security approaches rely on patching vulnerabilities after they are discovered. This leaves a window of vulnerability between the discovery and patching of the exploit.",[192],{"type":29,"attrs":193},{"color":90},{"type":20,"attrs":195,"content":196},{"textAlign":22},[197],{"text":198,"type":26,"marks":199},"Terniion offers a different approach.",[200],{"type":29,"attrs":201},{"color":90},{"type":157,"attrs":203,"content":204},{"level":178,"textAlign":22},[205],{"text":206,"type":26,"marks":207},"Xiid Terniion: A Secure Communication Platform",[208,210],{"type":29,"attrs":209},{"color":90},{"type":167},{"type":20,"attrs":212,"content":213},{"textAlign":22},[214],{"text":215,"type":26,"marks":216},"Terniion secures the communication channel between your GitLab server and authorized developer machines and, critically, makes the GitLab server available for legitimate use but completely unreachable by outside attackers. It achieves this through two key mechanisms:",[217],{"type":29,"attrs":218},{"color":90},{"type":220,"content":221},"bullet_list",[222,251],{"type":223,"content":224},"list_item",[225],{"type":20,"attrs":226,"content":227},{"textAlign":22},[228,234,239,240,249],{"text":229,"type":26,"marks":230},"Closed Inbound Firewall Ports:",[231,233],{"type":29,"attrs":232},{"color":90},{"type":167},{"text":235,"type":26,"marks":236}," Terniion, with its patented SealedTunnel technology, allows all inbound firewall ports to be closed on resources, creating a digital fortress around your GitLab instance. Since resources will no longer need public IP addresses, this virtually eliminates the attack surface, making it nearly impossible for attackers to exploit vulnerabilities like CVE-2024–4835 or CVE-2023–7028. In fact,",[237],{"type":29,"attrs":238},{"color":90},{"text":104,"type":26},{"text":241,"type":26,"marks":242},"that’s how Xiid uses GitLab",[243,246,248],{"type":95,"attrs":244},{"href":245,"uuid":22,"anchor":22,"target":22,"linktype":98},"https:\u002F\u002Fmxtoolbox.com\u002FSuperTool.aspx?action=a%3Agitlab02.xiid.com&run=toolpage",{"type":29,"attrs":247},{"color":76},{"type":102},{"text":250,"type":26},".",{"type":223,"content":252},[253],{"type":20,"attrs":254,"content":255},{"textAlign":22},[256,262],{"text":257,"type":26,"marks":258},"Quantum-Secure Encryption:",[259,261],{"type":29,"attrs":260},{"color":90},{"type":167},{"text":263,"type":26,"marks":264}," For authorized users, Terniion establishes a secure connection using triple-layer quantum-secure encryption. This encryption method utilizes complex mathematical algorithms that are currently considered unbreakable by even the most powerful computers. This ensures the confidentiality and integrity of data transmitted between your browser and the GitLab server.",[265],{"type":29,"attrs":266},{"color":90},{"type":157,"attrs":268,"content":269},{"level":178,"textAlign":22},[270],{"text":271,"type":26,"marks":272},"Benefits of Proactive Security with Terniion",[273],{"type":167},{"type":220,"content":275},[276,292],{"type":223,"content":277},[278],{"type":20,"attrs":279,"content":280},{"textAlign":22},[281,287],{"text":282,"type":26,"marks":283},"Zero-Day Defense:",[284,286],{"type":29,"attrs":285},{"color":90},{"type":167},{"text":288,"type":26,"marks":289}," By eliminating the attack surface and encrypting communication, Terniion offers protection from both known and unknown vulnerabilities. Even if a new exploit emerges (a zero-day attack), the encrypted tunnel remains secure and the vulnerable resource is unreachable by malicious actors.",[290],{"type":29,"attrs":291},{"color":90},{"type":223,"content":293},[294],{"type":20,"attrs":295,"content":296},{"textAlign":22},[297,303],{"text":298,"type":26,"marks":299},"Reduced Reliance on Patching",[300,302],{"type":29,"attrs":301},{"color":90},{"type":167},{"text":304,"type":26,"marks":305},": While patching remains important, Terniion offers a valuable safety net, reducing the urgency of immediate patching for known vulnerabilities.",[306],{"type":29,"attrs":307},{"color":90},{"type":157,"attrs":309,"content":310},{"level":178,"textAlign":22},[311],{"text":312,"type":26,"marks":313},"Terniion: A Part of a Layered Security Strategy",[314,316],{"type":29,"attrs":315},{"color":90},{"type":167},{"type":20,"attrs":318,"content":319},{"textAlign":22},[320],{"text":321,"type":26,"marks":322},"It’s important to remember that Terniion is not a silver bullet. Security best practices like keeping software updated and maintaining strong user authentication are still essential. However, by adding a layer of proactive defense through secure communication channels, the platform empowers developers to work with greater confidence, knowing their data and intellectual property are shielded from a wide range of threats.",[323],{"type":29,"attrs":324},{"color":90},"BlogPost",{"id":327,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":328,"copyright":76,"fieldtype":329,"meta_data":330,"is_external_url":15},187886411062029,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F5599x3733\u002Ffee7092d5e\u002Fpankaj-patel-zv_64ldgoao-unsplash-1.jpg","asset",{},{"type":17,"content":332},[333],{"type":220,"content":334},[335,342,349],{"type":223,"content":336},[337],{"type":20,"attrs":338,"content":339},{"textAlign":22},[340],{"text":341,"type":26},"CVE-2024-4835 (XSS) and CVE-2023-7028 (account takeover) are only exploitable if the GitLab server is publicly reachable. Remove reachability, and the CVEs become irrelevant.",{"type":223,"content":343},[344],{"type":20,"attrs":345,"content":346},{"textAlign":22},[347],{"text":348,"type":26},"Terniion makes GitLab servers unreachable to unauthorized parties while keeping them fully accessible to authorized developers, closing all inbound ports.",{"type":223,"content":350},[351],{"type":20,"attrs":352,"content":353},{"textAlign":22},[354],{"text":355,"type":26},"This approach provides zero-day defense: even unknown future vulnerabilities can't be exploited against infrastructure that has no public IP and accepts no inbound traffic.",{"id":327,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":328,"copyright":76,"fieldtype":329,"meta_data":357,"is_external_url":15},{},[359],{"_uid":360,"variant":361,"resource":362,"component":903,"hideLabel":15,"background":904},"7ca56c5c-5026-4210-98ce-327d27cf337d","oneThirdLeftPhoto",[363],{"name":364,"created_at":365,"published_at":366,"updated_at":367,"id":368,"uuid":369,"content":370,"slug":893,"full_slug":894,"sort_by_date":895,"position":896,"tag_list":897,"is_startpage":15,"parent_id":898,"meta_data":22,"group_id":899,"first_published_at":900,"release_id":22,"lang":39,"path":22,"alternates":901,"default_full_slug":22,"translated_slugs":22,"_stopResolving":902},"Compliance Isn’t Security (PQC Edition)","2026-06-15T22:59:27.475Z","2026-07-27T21:07:27.390Z","2026-07-27T21:07:27.406Z",187903047595078,"e9c0f618-21bb-4052-8350-cce98ec014d9",{"Tags":76,"_uid":77,"body":371,"title":372,"content":373,"component":325,"seoOgImage":859,"keyTakeaways":863,"previewImage":888,"previewTitle":364,"relatedContent":890,"seoDescription":891,"previewDescription":892},[],"Compliance isn’t security (PQC edition)",{"type":17,"content":374},[375,380,385,390,395,402,407,412,435,440,447,452,482,487,494,499,522,527,534,539,562,569,574,597,602,609,614,644,649,672,677,684,689,712,717,740,745,752,757,787,792,799,804,834,841,852,857],{"type":157,"attrs":376,"content":377},{"level":159,"textAlign":22},[378],{"text":379,"type":26},"Don’t Get Lulled into a False Sense of Security by Your OpenSSL Upgrade",{"type":20,"attrs":381,"content":382},{"textAlign":22},[383],{"text":384,"type":26},"Post-quantum cryptography (PQC) is rapidly moving from academic discussion to production reality. Standards are emerging. Libraries are adding hybrid algorithms. Vendors are announcing “quantum-ready” features.",{"type":20,"attrs":386,"content":387},{"textAlign":22},[388],{"text":389,"type":26},"If you recently upgraded OpenSSL and noticed support for hybrid key exchanges like mlkem768_x25519, that’s good news. But it’s not the finish line. In fact, believing that a single cryptographic library upgrade makes your infrastructure “quantum-secure” is one of the most dangerous misconceptions emerging in 2026.",{"type":20,"attrs":391,"content":392},{"textAlign":22},[393],{"text":394,"type":26},"Because PQC is not a library problem - it’s an architecture problem.",{"type":157,"attrs":396,"content":397},{"level":159,"textAlign":22},[398],{"text":399,"type":26,"marks":400},"The Core Misconception",[401],{"type":167},{"type":20,"attrs":403,"content":404},{"textAlign":22},[405],{"text":406,"type":26},"Modern OpenSSL releases now support hybrid classical + post-quantum key exchange algorithms. This means TLS sessions can negotiate quantum-resistant key material.",{"type":20,"attrs":408,"content":409},{"textAlign":22},[410],{"text":411,"type":26},"That is important progress. However, it assumes correct configuration everywhere and only protects the outermost transport layer. It does not address:",{"type":220,"content":413},[414,421,428],{"type":223,"content":415},[416],{"type":20,"attrs":417,"content":418},{"textAlign":22},[419],{"text":420,"type":26},"Application-layer security",{"type":223,"content":422},[423],{"type":20,"attrs":424,"content":425},{"textAlign":22},[426],{"text":427,"type":26},"Identity binding",{"type":223,"content":429},[430],{"type":20,"attrs":431,"content":432},{"textAlign":22},[433],{"text":434,"type":26},"End-to-end secrecy",{"type":20,"attrs":436,"content":437},{"textAlign":22},[438],{"text":439,"type":26},"You’ve added stronger bricks to your toolbox, but you have not rebuilt the house.",{"type":157,"attrs":441,"content":442},{"level":159,"textAlign":22},[443],{"text":444,"type":26,"marks":445},"Why Transport-Layer PQC Alone Is Not Enough",[446],{"type":167},{"type":20,"attrs":448,"content":449},{"textAlign":22},[450],{"text":451,"type":26},"Even with PQC-capable TLS:",{"type":220,"content":453},[454,461,468,475],{"type":223,"content":455},[456],{"type":20,"attrs":457,"content":458},{"textAlign":22},[459],{"text":460,"type":26},"Traffic may still be decrypted inside infrastructure components",{"type":223,"content":462},[463],{"type":20,"attrs":464,"content":465},{"textAlign":22},[466],{"text":467,"type":26},"Proxies, brokers, or gateways may terminate TLS, becoming ideal exfiltration points for any traffic flowing through them",{"type":223,"content":469},[470],{"type":20,"attrs":471,"content":472},{"textAlign":22},[473],{"text":474,"type":26},"Internal services may re-encrypt with classical cryptographic algorithms or cipher-suites",{"type":223,"content":476},[477],{"type":20,"attrs":478,"content":479},{"textAlign":22},[480],{"text":481,"type":26},"Applications may only handle plaintext, thus requiring preemptive decryption just to simply function",{"type":20,"attrs":483,"content":484},{"textAlign":22},[485],{"text":486,"type":26},"From an attacker’s perspective, any place where plaintext or classical encryption appears becomes the weak link. Quantum-safe at the edge does not equal quantum-safe end-to-end.",{"type":157,"attrs":488,"content":489},{"level":159,"textAlign":22},[490],{"text":491,"type":26,"marks":492},"PQC Requires Defense in Depth",[493],{"type":167},{"type":20,"attrs":495,"content":496},{"textAlign":22},[497],{"text":498,"type":26},"True post-quantum security must assume that any single layer can fail or be compromised. That means designing systems where:",{"type":220,"content":500},[501,508,515],{"type":223,"content":502},[503],{"type":20,"attrs":504,"content":505},{"textAlign":22},[506],{"text":507,"type":26},"No single component has full visibility",{"type":223,"content":509},[510],{"type":20,"attrs":511,"content":512},{"textAlign":22},[513],{"text":514,"type":26},"No single key exposes meaningful data",{"type":223,"content":516},[517],{"type":20,"attrs":518,"content":519},{"textAlign":22},[520],{"text":521,"type":26},"Compromise does not cascade",{"type":20,"attrs":523,"content":524},{"textAlign":22},[525],{"text":526,"type":26},"This is the design philosophy behind SealedTunnel, the heart of the Terniion platform.",{"type":157,"attrs":528,"content":529},{"level":159,"textAlign":22},[530],{"text":531,"type":26,"marks":532},"SealedTunnel: Post-Quantum Security by Architecture, Not Checkbox",[533],{"type":167},{"type":20,"attrs":535,"content":536},{"textAlign":22},[537],{"text":538,"type":26},"SealedTunnel is built around a simple principle: Security must be process-to-process, layered, and cryptographically agile, not:",{"type":220,"content":540},[541,548,555],{"type":223,"content":542},[543],{"type":20,"attrs":544,"content":545},{"textAlign":22},[546],{"text":547,"type":26},"Device-to-device",{"type":223,"content":549},[550],{"type":20,"attrs":551,"content":552},{"textAlign":22},[553],{"text":554,"type":26},"Network-to-network",{"type":223,"content":556},[557],{"type":20,"attrs":558,"content":559},{"textAlign":22},[560],{"text":561,"type":26},"Encrypted “somewhere along the path”",{"type":157,"attrs":563,"content":564},{"level":178,"textAlign":22},[565],{"text":566,"type":26,"marks":567},"Process-to-Process Validation",[568],{"type":167},{"type":20,"attrs":570,"content":571},{"textAlign":22},[572],{"text":573,"type":26},"Before any tunnel exists, both endpoint agents validate:",{"type":220,"content":575},[576,583,590],{"type":223,"content":577},[578],{"type":20,"attrs":579,"content":580},{"textAlign":22},[581],{"text":582,"type":26},"The identity of the requesting process",{"type":223,"content":584},[585],{"type":20,"attrs":586,"content":587},{"textAlign":22},[588],{"text":589,"type":26},"The integrity of the process",{"type":223,"content":591},[592],{"type":20,"attrs":593,"content":594},{"textAlign":22},[595],{"text":596,"type":26},"Authorization to establish a tunnel",{"type":20,"attrs":598,"content":599},{"textAlign":22},[600],{"text":601,"type":26},"This eliminates an entire class of attacks where malware piggybacks on legitimate network access. If the process is not trusted, no tunnel exists.",{"type":157,"attrs":603,"content":604},{"level":178,"textAlign":22},[605],{"text":606,"type":26,"marks":607},"Layer 1 — Quantum-Safe Transport to the Fabric",[608],{"type":167},{"type":20,"attrs":610,"content":611},{"textAlign":22},[612],{"text":613,"type":26},"Each agent establishes an outbound-only connection to the Xiid brokerage fabric using:",{"type":220,"content":615},[616,623,630,637],{"type":223,"content":617},[618],{"type":20,"attrs":619,"content":620},{"textAlign":22},[621],{"text":622,"type":26},"TLS 1.3",{"type":223,"content":624},[625],{"type":20,"attrs":626,"content":627},{"textAlign":22},[628],{"text":629,"type":26},"Perfect Forward Secrecy",{"type":223,"content":631},[632],{"type":20,"attrs":633,"content":634},{"textAlign":22},[635],{"text":636,"type":26},"Mutual X.509 certificate authentication",{"type":223,"content":638},[639],{"type":20,"attrs":640,"content":641},{"textAlign":22},[642],{"text":643,"type":26},"Hybrid PQC key exchange (mlkem768_x25519)",{"type":20,"attrs":645,"content":646},{"textAlign":22},[647],{"text":648,"type":26},"This ensures:",{"type":220,"content":650},[651,658,665],{"type":223,"content":652},[653],{"type":20,"attrs":654,"content":655},{"textAlign":22},[656],{"text":657,"type":26},"No inbound firewall holes",{"type":223,"content":659},[660],{"type":20,"attrs":661,"content":662},{"textAlign":22},[663],{"text":664,"type":26},"No static exposure",{"type":223,"content":666},[667],{"type":20,"attrs":668,"content":669},{"textAlign":22},[670],{"text":671,"type":26},"No classical-only key material",{"type":20,"attrs":673,"content":674},{"textAlign":22},[675],{"text":676,"type":26},"At this stage, communication is already quantum-resistant. But we don’t stop here.",{"type":157,"attrs":678,"content":679},{"level":178,"textAlign":22},[680],{"text":681,"type":26,"marks":682},"Layer 2 — End-to-End Post-Quantum Key Exchange",[683],{"type":167},{"type":20,"attrs":685,"content":686},{"textAlign":22},[687],{"text":688,"type":26},"Once both agents are connected, a second key exchange occurs directly between the two endpoints not through the fabric. This exchange:",{"type":220,"content":690},[691,698,705],{"type":223,"content":692},[693],{"type":20,"attrs":694,"content":695},{"textAlign":22},[696],{"text":697,"type":26},"Uses hybrid PQC (mlkem768_x25519)",{"type":223,"content":699},[700],{"type":20,"attrs":701,"content":702},{"textAlign":22},[703],{"text":704,"type":26},"Establishes an end-to-end ephemeral secret",{"type":223,"content":706},[707],{"type":20,"attrs":708,"content":709},{"textAlign":22},[710],{"text":711,"type":26},"Cuts the fabric completely out of the trust boundary",{"type":20,"attrs":713,"content":714},{"textAlign":22},[715],{"text":716,"type":26},"The fabric becomes a blind packet forwarder. It cannot:",{"type":220,"content":718},[719,726,733],{"type":223,"content":720},[721],{"type":20,"attrs":722,"content":723},{"textAlign":22},[724],{"text":725,"type":26},"Decrypt",{"type":223,"content":727},[728],{"type":20,"attrs":729,"content":730},{"textAlign":22},[731],{"text":732,"type":26},"Inspect",{"type":223,"content":734},[735],{"type":20,"attrs":736,"content":737},{"textAlign":22},[738],{"text":739,"type":26},"Influence key material",{"type":20,"attrs":741,"content":742},{"textAlign":22},[743],{"text":744,"type":26},"This is true end-to-end encryption.",{"type":157,"attrs":746,"content":747},{"level":178,"textAlign":22},[748],{"text":749,"type":26,"marks":750},"Layer 3 — Rolling Ephemeral Encryption",[751],{"type":167},{"type":20,"attrs":753,"content":754},{"textAlign":22},[755],{"text":756,"type":26},"From the end-to-end ephemeral secret, SealedTunnel continuously derives rolling ephemeral keys. Rotation can be based on time or the amount of transferred data. These keys are then used for AES-256-GCM (AEAD), which provides:",{"type":220,"content":758},[759,766,773,780],{"type":223,"content":760},[761],{"type":20,"attrs":762,"content":763},{"textAlign":22},[764],{"text":765,"type":26},"Confidentiality",{"type":223,"content":767},[768],{"type":20,"attrs":769,"content":770},{"textAlign":22},[771],{"text":772,"type":26},"Integrity",{"type":223,"content":774},[775],{"type":20,"attrs":776,"content":777},{"textAlign":22},[778],{"text":779,"type":26},"Authentication",{"type":223,"content":781},[782],{"type":20,"attrs":783,"content":784},{"textAlign":22},[785],{"text":786,"type":26},"Proven resistance even under quantum attack models",{"type":20,"attrs":788,"content":789},{"textAlign":22},[790],{"text":791,"type":26},"This renders “Harvest Now, Decrypt Later” (HNDL) attacks effectively useless.",{"type":157,"attrs":793,"content":794},{"level":178,"textAlign":22},[795],{"text":796,"type":26,"marks":797},"Built for Cryptographic Agility",[798],{"type":167},{"type":20,"attrs":800,"content":801},{"textAlign":22},[802],{"text":803,"type":26},"Rather than being tied to one algorithm, SealedTunnel architecture allows:",{"type":220,"content":805},[806,813,820,827],{"type":223,"content":807},[808],{"type":20,"attrs":809,"content":810},{"textAlign":22},[811],{"text":812,"type":26},"Algorithms to be swapped",{"type":223,"content":814},[815],{"type":20,"attrs":816,"content":817},{"textAlign":22},[818],{"text":819,"type":26},"Parameters to evolve",{"type":223,"content":821},[822],{"type":20,"attrs":823,"content":824},{"textAlign":22},[825],{"text":826,"type":26},"Hybrid modes to be adjusted",{"type":223,"content":828},[829],{"type":20,"attrs":830,"content":831},{"textAlign":22},[832],{"text":833,"type":26},"Future PQC standards to be introduced without redesign",{"type":157,"attrs":835,"content":836},{"level":159,"textAlign":22},[837],{"text":838,"type":26,"marks":839},"The Final Takeaway",[840],{"type":167},{"type":20,"attrs":842,"content":843},{"textAlign":22},[844,846,851],{"text":845,"type":26},"Post-quantum security is not achieved by a checkbox, a version number, or a single library upgrade. It is achieved by layered, end-to-end, process-bound architecture that is secure ",{"text":847,"type":26,"marks":848},"by design",[849],{"type":850},"italic",{"text":250,"type":26},{"type":20,"attrs":853,"content":854},{"textAlign":22},[855],{"text":856,"type":26},"If your PQC story begins and ends with “we upgraded OpenSSL,” you haven’t solved the problem. You’ve only started thinking about it. SealedTunnel technology exists because starting to think is not enough.",{"type":20,"attrs":858},{"textAlign":22},{"id":860,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":861,"copyright":76,"fieldtype":329,"meta_data":862,"is_external_url":15},187903655050848,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F4496x3000\u002F8bffabb58a\u002Fthisguyshoots-ldyoooug5wi-unsplash.jpg",{},{"type":17,"content":864},[865],{"type":220,"content":866},[867,874,881],{"type":223,"content":868},[869],{"type":20,"attrs":870,"content":871},{"textAlign":22},[872],{"text":873,"type":26},"Post-quantum cryptography compliance deadlines (NIST standards, government mandates) are arriving faster than most organizations realize.",{"type":223,"content":875},[876],{"type":20,"attrs":877,"content":878},{"textAlign":22},[879],{"text":880,"type":26},"Checking a compliance box for PQC doesn't mean communications are actually quantum-secure. Many implementations are hybrid or incomplete.",{"type":223,"content":882},[883],{"type":20,"attrs":884,"content":885},{"textAlign":22},[886],{"text":887,"type":26},"Terniion's triple-layer encryption (including Kyber + Dilithium) is quantum-secure by architecture, not by retrofit.",{"id":860,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":861,"copyright":76,"fieldtype":329,"meta_data":889,"is_external_url":15},{},[],"A cryptographic library upgrade fails to make infrastructure quantum-secure - you need to do more than the OpenSSL upgrade.","This blog explains why simply upgrading your OpenSSL does not achieve post-quantum resilience or protection. ","compliance-isnt-security-pqc-openssl-upgrade","blog\u002Fcompliance-isnt-security-pqc-openssl-upgrade","2026-02-19",80,[],193139877037850,"e896fbe9-4af9-417f-9a7a-55ed5fb7dced","2026-02-19T10:55:00.000Z",[],true,"ResourceFeatureCard","white","Learn how Xiid Terniion makes GitLab servers unreachable by attackers, blocks XSS and account takeover exploits, and delivers quantum-secure, zero-day-proof communication.","Gitlab’s XSS vulnerability allows attackers to inject malicious scripts into legitimate web pages, potentially stealing sensitive user or corporate data.","securing-gitlab-from-xss-and-account-takeover-attacks","blog\u002Fsecuring-gitlab-from-xss-and-account-takeover-attacks","2025-04-02",160,[],"9ad71f90-4c7c-43e0-8e6c-2d00c58a8d36","2025-04-02T09:00:00.000Z",[],[916],{"name":364,"created_at":365,"published_at":366,"updated_at":367,"id":368,"uuid":369,"content":917,"slug":893,"full_slug":894,"sort_by_date":895,"position":896,"tag_list":1358,"is_startpage":15,"parent_id":898,"meta_data":22,"group_id":899,"first_published_at":900,"release_id":22,"lang":39,"path":22,"alternates":1359,"default_full_slug":22,"translated_slugs":22},{"Tags":76,"_uid":77,"body":918,"title":372,"content":919,"component":325,"seoOgImage":1331,"keyTakeaways":1333,"previewImage":1355,"previewTitle":364,"relatedContent":1357,"seoDescription":891,"previewDescription":892},[],{"type":17,"content":920},[921,925,929,933,937,943,947,951,971,975,981,985,1011,1015,1021,1025,1045,1049,1055,1059,1079,1085,1089,1109,1113,1119,1123,1149,1153,1173,1177,1183,1187,1207,1211,1231,1235,1241,1245,1271,1275,1281,1285,1311,1317,1325,1329],{"type":157,"attrs":922,"content":923},{"level":159,"textAlign":22},[924],{"text":379,"type":26},{"type":20,"attrs":926,"content":927},{"textAlign":22},[928],{"text":384,"type":26},{"type":20,"attrs":930,"content":931},{"textAlign":22},[932],{"text":389,"type":26},{"type":20,"attrs":934,"content":935},{"textAlign":22},[936],{"text":394,"type":26},{"type":157,"attrs":938,"content":939},{"level":159,"textAlign":22},[940],{"text":399,"type":26,"marks":941},[942],{"type":167},{"type":20,"attrs":944,"content":945},{"textAlign":22},[946],{"text":406,"type":26},{"type":20,"attrs":948,"content":949},{"textAlign":22},[950],{"text":411,"type":26},{"type":220,"content":952},[953,959,965],{"type":223,"content":954},[955],{"type":20,"attrs":956,"content":957},{"textAlign":22},[958],{"text":420,"type":26},{"type":223,"content":960},[961],{"type":20,"attrs":962,"content":963},{"textAlign":22},[964],{"text":427,"type":26},{"type":223,"content":966},[967],{"type":20,"attrs":968,"content":969},{"textAlign":22},[970],{"text":434,"type":26},{"type":20,"attrs":972,"content":973},{"textAlign":22},[974],{"text":439,"type":26},{"type":157,"attrs":976,"content":977},{"level":159,"textAlign":22},[978],{"text":444,"type":26,"marks":979},[980],{"type":167},{"type":20,"attrs":982,"content":983},{"textAlign":22},[984],{"text":451,"type":26},{"type":220,"content":986},[987,993,999,1005],{"type":223,"content":988},[989],{"type":20,"attrs":990,"content":991},{"textAlign":22},[992],{"text":460,"type":26},{"type":223,"content":994},[995],{"type":20,"attrs":996,"content":997},{"textAlign":22},[998],{"text":467,"type":26},{"type":223,"content":1000},[1001],{"type":20,"attrs":1002,"content":1003},{"textAlign":22},[1004],{"text":474,"type":26},{"type":223,"content":1006},[1007],{"type":20,"attrs":1008,"content":1009},{"textAlign":22},[1010],{"text":481,"type":26},{"type":20,"attrs":1012,"content":1013},{"textAlign":22},[1014],{"text":486,"type":26},{"type":157,"attrs":1016,"content":1017},{"level":159,"textAlign":22},[1018],{"text":491,"type":26,"marks":1019},[1020],{"type":167},{"type":20,"attrs":1022,"content":1023},{"textAlign":22},[1024],{"text":498,"type":26},{"type":220,"content":1026},[1027,1033,1039],{"type":223,"content":1028},[1029],{"type":20,"attrs":1030,"content":1031},{"textAlign":22},[1032],{"text":507,"type":26},{"type":223,"content":1034},[1035],{"type":20,"attrs":1036,"content":1037},{"textAlign":22},[1038],{"text":514,"type":26},{"type":223,"content":1040},[1041],{"type":20,"attrs":1042,"content":1043},{"textAlign":22},[1044],{"text":521,"type":26},{"type":20,"attrs":1046,"content":1047},{"textAlign":22},[1048],{"text":526,"type":26},{"type":157,"attrs":1050,"content":1051},{"level":159,"textAlign":22},[1052],{"text":531,"type":26,"marks":1053},[1054],{"type":167},{"type":20,"attrs":1056,"content":1057},{"textAlign":22},[1058],{"text":538,"type":26},{"type":220,"content":1060},[1061,1067,1073],{"type":223,"content":1062},[1063],{"type":20,"attrs":1064,"content":1065},{"textAlign":22},[1066],{"text":547,"type":26},{"type":223,"content":1068},[1069],{"type":20,"attrs":1070,"content":1071},{"textAlign":22},[1072],{"text":554,"type":26},{"type":223,"content":1074},[1075],{"type":20,"attrs":1076,"content":1077},{"textAlign":22},[1078],{"text":561,"type":26},{"type":157,"attrs":1080,"content":1081},{"level":178,"textAlign":22},[1082],{"text":566,"type":26,"marks":1083},[1084],{"type":167},{"type":20,"attrs":1086,"content":1087},{"textAlign":22},[1088],{"text":573,"type":26},{"type":220,"content":1090},[1091,1097,1103],{"type":223,"content":1092},[1093],{"type":20,"attrs":1094,"content":1095},{"textAlign":22},[1096],{"text":582,"type":26},{"type":223,"content":1098},[1099],{"type":20,"attrs":1100,"content":1101},{"textAlign":22},[1102],{"text":589,"type":26},{"type":223,"content":1104},[1105],{"type":20,"attrs":1106,"content":1107},{"textAlign":22},[1108],{"text":596,"type":26},{"type":20,"attrs":1110,"content":1111},{"textAlign":22},[1112],{"text":601,"type":26},{"type":157,"attrs":1114,"content":1115},{"level":178,"textAlign":22},[1116],{"text":606,"type":26,"marks":1117},[1118],{"type":167},{"type":20,"attrs":1120,"content":1121},{"textAlign":22},[1122],{"text":613,"type":26},{"type":220,"content":1124},[1125,1131,1137,1143],{"type":223,"content":1126},[1127],{"type":20,"attrs":1128,"content":1129},{"textAlign":22},[1130],{"text":622,"type":26},{"type":223,"content":1132},[1133],{"type":20,"attrs":1134,"content":1135},{"textAlign":22},[1136],{"text":629,"type":26},{"type":223,"content":1138},[1139],{"type":20,"attrs":1140,"content":1141},{"textAlign":22},[1142],{"text":636,"type":26},{"type":223,"content":1144},[1145],{"type":20,"attrs":1146,"content":1147},{"textAlign":22},[1148],{"text":643,"type":26},{"type":20,"attrs":1150,"content":1151},{"textAlign":22},[1152],{"text":648,"type":26},{"type":220,"content":1154},[1155,1161,1167],{"type":223,"content":1156},[1157],{"type":20,"attrs":1158,"content":1159},{"textAlign":22},[1160],{"text":657,"type":26},{"type":223,"content":1162},[1163],{"type":20,"attrs":1164,"content":1165},{"textAlign":22},[1166],{"text":664,"type":26},{"type":223,"content":1168},[1169],{"type":20,"attrs":1170,"content":1171},{"textAlign":22},[1172],{"text":671,"type":26},{"type":20,"attrs":1174,"content":1175},{"textAlign":22},[1176],{"text":676,"type":26},{"type":157,"attrs":1178,"content":1179},{"level":178,"textAlign":22},[1180],{"text":681,"type":26,"marks":1181},[1182],{"type":167},{"type":20,"attrs":1184,"content":1185},{"textAlign":22},[1186],{"text":688,"type":26},{"type":220,"content":1188},[1189,1195,1201],{"type":223,"content":1190},[1191],{"type":20,"attrs":1192,"content":1193},{"textAlign":22},[1194],{"text":697,"type":26},{"type":223,"content":1196},[1197],{"type":20,"attrs":1198,"content":1199},{"textAlign":22},[1200],{"text":704,"type":26},{"type":223,"content":1202},[1203],{"type":20,"attrs":1204,"content":1205},{"textAlign":22},[1206],{"text":711,"type":26},{"type":20,"attrs":1208,"content":1209},{"textAlign":22},[1210],{"text":716,"type":26},{"type":220,"content":1212},[1213,1219,1225],{"type":223,"content":1214},[1215],{"type":20,"attrs":1216,"content":1217},{"textAlign":22},[1218],{"text":725,"type":26},{"type":223,"content":1220},[1221],{"type":20,"attrs":1222,"content":1223},{"textAlign":22},[1224],{"text":732,"type":26},{"type":223,"content":1226},[1227],{"type":20,"attrs":1228,"content":1229},{"textAlign":22},[1230],{"text":739,"type":26},{"type":20,"attrs":1232,"content":1233},{"textAlign":22},[1234],{"text":744,"type":26},{"type":157,"attrs":1236,"content":1237},{"level":178,"textAlign":22},[1238],{"text":749,"type":26,"marks":1239},[1240],{"type":167},{"type":20,"attrs":1242,"content":1243},{"textAlign":22},[1244],{"text":756,"type":26},{"type":220,"content":1246},[1247,1253,1259,1265],{"type":223,"content":1248},[1249],{"type":20,"attrs":1250,"content":1251},{"textAlign":22},[1252],{"text":765,"type":26},{"type":223,"content":1254},[1255],{"type":20,"attrs":1256,"content":1257},{"textAlign":22},[1258],{"text":772,"type":26},{"type":223,"content":1260},[1261],{"type":20,"attrs":1262,"content":1263},{"textAlign":22},[1264],{"text":779,"type":26},{"type":223,"content":1266},[1267],{"type":20,"attrs":1268,"content":1269},{"textAlign":22},[1270],{"text":786,"type":26},{"type":20,"attrs":1272,"content":1273},{"textAlign":22},[1274],{"text":791,"type":26},{"type":157,"attrs":1276,"content":1277},{"level":178,"textAlign":22},[1278],{"text":796,"type":26,"marks":1279},[1280],{"type":167},{"type":20,"attrs":1282,"content":1283},{"textAlign":22},[1284],{"text":803,"type":26},{"type":220,"content":1286},[1287,1293,1299,1305],{"type":223,"content":1288},[1289],{"type":20,"attrs":1290,"content":1291},{"textAlign":22},[1292],{"text":812,"type":26},{"type":223,"content":1294},[1295],{"type":20,"attrs":1296,"content":1297},{"textAlign":22},[1298],{"text":819,"type":26},{"type":223,"content":1300},[1301],{"type":20,"attrs":1302,"content":1303},{"textAlign":22},[1304],{"text":826,"type":26},{"type":223,"content":1306},[1307],{"type":20,"attrs":1308,"content":1309},{"textAlign":22},[1310],{"text":833,"type":26},{"type":157,"attrs":1312,"content":1313},{"level":159,"textAlign":22},[1314],{"text":838,"type":26,"marks":1315},[1316],{"type":167},{"type":20,"attrs":1318,"content":1319},{"textAlign":22},[1320,1321,1324],{"text":845,"type":26},{"text":847,"type":26,"marks":1322},[1323],{"type":850},{"text":250,"type":26},{"type":20,"attrs":1326,"content":1327},{"textAlign":22},[1328],{"text":856,"type":26},{"type":20,"attrs":1330},{"textAlign":22},{"id":860,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":861,"copyright":76,"fieldtype":329,"meta_data":1332,"is_external_url":15},{},{"type":17,"content":1334},[1335],{"type":220,"content":1336},[1337,1343,1349],{"type":223,"content":1338},[1339],{"type":20,"attrs":1340,"content":1341},{"textAlign":22},[1342],{"text":873,"type":26},{"type":223,"content":1344},[1345],{"type":20,"attrs":1346,"content":1347},{"textAlign":22},[1348],{"text":880,"type":26},{"type":223,"content":1350},[1351],{"type":20,"attrs":1352,"content":1353},{"textAlign":22},[1354],{"text":887,"type":26},{"id":860,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":861,"copyright":76,"fieldtype":329,"meta_data":1356,"is_external_url":15},{},[],[],[],[],{"cache-control":46,"connection":47,"content-encoding":1362,"content-type":49,"date":1363,"etag":1364,"referrer-policy":52,"sb-be-version":53,"server":54,"transfer-encoding":1365,"vary":1366,"via":1367,"x-amz-cf-id":1368,"x-amz-cf-pop":58,"x-cache":59,"x-content-type-options":60,"x-frame-options":61,"x-permitted-cross-domain-policies":62,"x-request-id":1369,"x-runtime":1370,"x-xss-protection":65},"gzip","Wed, 12 Aug 2026 16:32:30 GMT","W\u002F\"c095fc7c7f67c6d8a8bde248cb65ea1c\"","chunked","Origin,Accept-Encoding","1.1 4dfaf20d3a2c1a50aae39c582b50b700.cloudfront.net (CloudFront)","hdLHM0VUPoyHdcyZ1PXRyrW4JuUxgjFNHqXDOT-MVFGkyjokKkYojA==","4ee525c3-7fc9-492b-88f1-4749635e9189","0.034651",1786552350388]