Honest question that will probably sound like I'm trying to dunk on them but I'm not: Is this something anyone actually cares about? What's the theoretical concern? AitM SSH sessions? Decrypting past SSH sessions? Cracking private keys?
I honestly don't understand how whether the SSH config is PQC capable is a concern when these are already Internet-facing OT and medical devices.
Internet-wide PQC measurement: 160M SSH hosts scanned.
IT: 12% PQC-capable. OT: under 5%. Medical devices: under 5%. Cloud leads because providers deploy PQC by default. Everything else waits for manual upgrades nobody has scheduled.
The OT gap should alarm anyone in ICS/SCADA.
https://postquantum.com/security-pqc/forescout-pqc-adoption-data-2026/
#PQC #OTsecurity #ICS #infosec
