Cloudflare Unlocks Post-Quantum Encryption Visibility

Alps Wang

Alps Wang

Sep 29, 2026 · 1 views

Post-Quantum Readiness Unveiled

Cloudflare's introduction of post-quantum cryptography visibility tools is a timely and impactful move, directly addressing a critical gap in understanding the transition to quantum-resistant security. The ability for customers to inspect and graph the adoption of post-quantum TLS 1.3 encryption for their specific domains through Logpush, Log Explorer, and HTTP Traffic Analytics provides granular, actionable telemetry. This is invaluable for auditing compliance, assessing cryptographic posture, and identifying potential vulnerabilities, especially given the 2030 deprecation deadline for current standards. The hybrid ML-KEM approach offers a robust, layered security model, and the integration into existing Cloudflare products ensures accessibility for a wide user base. Furthermore, Cloudflare's commitment to making post-quantum encryption the default in many products and sharing internal learnings demonstrates leadership in this complex cryptographic transition.

However, a key limitation remains the reliance on hybrid encryption for the 'post-quantum' designation. While ML-KEM provides strong protection against quantum attacks on the key exchange, the article acknowledges that post-quantum authentication (signatures like ML-DSA) is still in earlier deployment stages. This means that while the communication channel's key agreement might be quantum-resistant, the integrity of the server's identity (certificates) could still be vulnerable to future quantum attacks. This distinction is crucial for organizations with extremely long-term data sensitivity. Additionally, the effectiveness of these tools is contingent on customers actively utilizing Cloudflare's logging and analytics features. For those not leveraging these services, the visibility remains externalized through Cloudflare Radar's aggregate data. The article also hints at the complexity for legacy systems, suggesting Cloudflare Tunnels as a workaround, which, while effective, adds another layer of configuration and management for some users.

Key Points

  • Cloudflare has launched new tools to provide visibility into post-quantum (PQ) cryptography adoption for TLS 1.3.
  • Customers can now inspect and graph PQ TLS 1.3 encryption for live traffic within Logpush, Log Explorer, and HTTP Traffic Analytics.
  • This allows granular, per-connection telemetry to audit PQ posture, assess compliance, and identify cryptographic gaps.
  • Cloudflare is targeting 2029 for full post-quantum security and aims to ease the transition by making PQ encryption the default in many products.
  • Global adoption metrics show ~70% of visitor-to-Cloudflare traffic uses PQ encryption, while only ~15% of Cloudflare-to-origin connections do.
  • The new features expose the key exchange algorithm negotiated on every incoming request, specifically identifying algorithms like X25519MLKEM768.
  • Post-quantum encryption is crucial to prevent "harvest-now-decrypt-later" attacks, especially for data valuable in 3-10 years.
  • The visibility extends to Cloudflare-to-origin connections with the OriginTLSKeyExchangeGroup field.
  • For legacy origin servers, Cloudflare Tunnels can provide PQ encryption without upgrading the origin itself.

Article Image


📖 Source: Is your domain using post-quantum encryption? Now you can see for yourself

Related Articles

Comments (0)

No comments yet. Be the first to comment!