For current work on postquantum handshake support in Tor, see
proposals 263, 269, 270, and ticket #24985.
A digression:
Personally, I don't agree that the evidence is so convincing about the
NSA being able to break 256-bit ECDSA today: if they have it, then
they'd treat it as a big secret, and no
honestly, ideally it would be a lot easier to do things with tor if it
actually internally followed the unix philosophy and the layers of service
could be used as a part of the linux system and modular use of the parts. I
was just looking at BGP routing over tor. I'm not sure how to do that with
th