Trending: On-device modelsSearch
iHeartGeek
iTECH

openSUSE Factory picks up ZUPT for post-quantum backups

The backup and compression utility pairs AES-256 with a hybrid ML-KEM-768 and X25519 scheme aimed at 'harvest now, decrypt later' threats.

Wooden letter tiles spelling the word encryption in a row on a pale surface, lit against a blurred green background

openSUSE's rolling development branch has a new option for encrypted backups. ZUPT, an open-source backup, compression and data-protection utility, has been accepted into openSUSE Factory, its author announced on 4 October.

One tool for making, checking and restoring archives

ZUPT packages files and directories into compact archives for storage, transfer, verification and restore, bundling creation, compression, integrity checking and encryption into a single command-line tool. It uses multithreaded processing to spread backup, compression and restore work across CPU cores, and ships commands for testing and validating what is inside an archive.

The post-quantum part

Encryption is the headline. Beyond AES-256, ZUPT supports a hybrid scheme that pairs ML-KEM-768, a post-quantum key-encapsulation mechanism, with the long-established X25519 elliptic-curve exchange. The combination is aimed squarely at 'harvest now, decrypt later' — the scenario in which encrypted data copied today is stored in the expectation that a future machine can eventually open it. For archives meant to sit untouched for years, that is the threat model that actually matters.

Why long-lived archives care

Backups are one of the few places where data is expected to outlive the hardware that produced it, which makes them an obvious candidate for post-quantum key agreement. ZUPT also verifies file integrity so corruption or an unexpected change inside an archive can be detected before a restore depends on it. The project is developed in the open, and the post announcing the Factory acceptance is published under a Creative Commons licence.

Our opinion

Post-quantum migration has mostly been a conversation about TLS handshakes and decade-long certificates, which makes the backup angle easy to underrate. A disk copied to cold storage this month could still be sitting on a shelf when the first genuinely useful quantum computer arrives, and nobody is going to re-encrypt it by hand.

The interesting call is the hybrid design. Pairing ML-KEM-768 with X25519 rather than going pure post-quantum is the conservative choice, and the right one while the newer schemes are still young enough to be worth doubting. Whether ZUPT ends up widely deployed matters less than the pattern it sets: quietly, the least glamorous tools in the stack are getting quantum-resistant key exchange first, and that is exactly where they should be.

Photo by Markus Winkler on Pexels.