← All stories
● Covered by 1 source · 4 reportsMedium impact4 neutral

Cloudflare Advances Post-Quantum Cryptography Migration with New Tools and IPsec Mitigation

🔄 Updated 21h ago — new reporting from Cloudflare Blog
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Cloudflare aims for full post-quantum readiness by 2029.
  • CryptoLabe, an internal AI tool, will manage the migration across Cloudflare's platform.
  • New customer tools provide visibility into post-quantum TLS 1.3 encryption adoption.
  • Cloudflare collaborated with IETF to mitigate quantum downgrade attacks on IPsec.
  • The migration addresses threats from future cryptographically relevant quantum computers.
  • Cloudflare Workers now supports ML-KEM and ML-DSA algorithms in its Web Crypto API.
  • ML-KEM-768 and ML-KEM-1024 are supported for key encapsulation.
  • ML-DSA-44, ML-DSA-65, and ML-DSA-87 are supported for signatures.
  • The support is available behind the webcrypto_modern_algorithms compatibility flag.

Cloudflare's Post-Quantum Readiness Initiative

Cloudflare is working towards a 2029 deadline for full post-quantum readiness across its platform. This initiative involves transitioning its products to post-quantum encryption and authentication to secure customer traffic against potential threats from future quantum computers. The company states it is taking a "PQ everything!" approach to provide future-proof security as an infrastructure provider.

Internal AI Tool for Migration Management

To manage the large-scale cryptographic migration, Cloudflare is developing an internal AI tool named CryptoLabe. This tool is designed to help product and engineering teams understand cryptographic usage, track migration progress, and identify dependencies on protocols that lack post-quantum plans. CryptoLabe will assist in upgrading to both post-quantum encryption and authentication.

Enhanced Visibility for Customers

Cloudflare has introduced new post-quantum cryptography visibility tools within its Application Security and Logs products. These tools allow customers to inspect and graph the adoption of post-quantum TLS 1.3 encryption for live traffic. Available through Logpush, Log Explorer, and the HTTP Traffic Analytics dashboard, these features provide per-connection telemetry for auditing post-quantum posture, assessing compliance, and identifying cryptographic gaps across domains.

Mitigating Quantum Downgrade Attacks on IPsec

In collaboration with the IETF, Cloudflare developed and implemented a mitigation against quantum downgrade attacks on IPsec. This addresses the risk where attackers could force connections to use weaker classical cryptography during the transition to post-quantum cryptography, making them vulnerable to future quantum computers. The mitigation has been implemented and is available in beta across Cloudflare's IPsec products.

Addressing Quantum Computing Threats

The migration to post-quantum cryptography is a response to the development of quantum computers, which are expected to be capable of cracking current cryptographic methods like Diffie-Hellman key agreement and classical signature schemes such as ECDSA and RSA. The goal is to replace these with post-quantum schemes like ML-KEM and ML-DSA, which are believed to be resistant to quantum attacks.

Updates

🕒 2026-10-01 · new reporting from Cloudflare Blog
  • Cloudflare Workers now supports ML-KEM and ML-DSA algorithms in its Web Crypto API.
  • ML-KEM-768 and ML-KEM-1024 are supported for key encapsulation.
  • ML-DSA-44, ML-DSA-65, and ML-DSA-87 are supported for signatures.
  • The support is available behind the webcrypto_modern_algorithms compatibility flag.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Cloudflare Workers now supports post-quantum-resistant algorithms like ML-KEM and ML-DSA within its Web Crypto API. This addition allows developers to experiment with these new cryptographic primitives without bundling separate implementations, aiding in the transition to post-quantum security.

Cloudflare is developing an internal AI tool, CryptoLabe, to manage its migration to post-quantum cryptography across its platform by 2029. The tool will help identify cryptographic usage, track migration progress, and flag dependencies on protocols without post-quantum plans. This initiative aims to secure Cloudflare's infrastructure and customer traffic against future quantum computing threats.

Cloudflare collaborated with the IETF to develop and implement a mitigation against quantum downgrade attacks on IPsec. This addresses the risk of attackers forcing connections to use weaker classical cryptography during the transition to post-quantum cryptography, which could be vulnerable to future quantum computers.

Cloudflare introduced new post-quantum (PQ) cryptography visibility tools within its Application Security and Logs products. These tools allow customers to inspect and graph the adoption of post-quantum TLS 1.3 encryption for live traffic, providing per-connection telemetry to audit their post-quantum posture and identify cryptographic gaps.