Meta has announced that its public time service, accessible at nts.meta.com, now supports Network Time Security (NTS), as defined by RFC 8915. This implementation allows devices to verify that time data originates from Meta and has not been tampered with during transmission. The NTS servers are designed to be stateless per client, with cookie keys derived rather than stored or replicated.
Meta has open-sourced its entire NTS implementation, including the protocol, server, and client components, through its Time library on GitHub. The company is encouraging developers, particularly those maintaining NTP clients on Android or iOS, to adopt and enable NTS support in their applications.
The Network Time Protocol (NTP) has operated without authentication since its inception in 1985, similar to many foundational internet protocols. This lack of authentication means that a client cannot verify the origin or integrity of time data received. However, accurate and verifiable time is crucial for modern internet security, as it underpins certificate validation, token and credential expiry, replay window management, and log correlation.
Time is a fundamental input against which many other security decisions are measured. Without authenticated time, critical security functions can be compromised. For example, certificate validation relies on accurate time to check 'notBefore' and 'notAfter' dates, and incorrect time can lead to false positives or negatives. Similarly, the validity of tokens and credentials, which often have time-limited lifespans, depends on a trusted time source. The introduction of NTS aims to mitigate these vulnerabilities by providing a verifiable time source.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Meta has enabled Network Time Security (NTS, RFC 8915) on its public time service, nts.meta.com, to authenticate time packets and prevent modification. This update addresses the long-standing vulnerability of unauthenticated NTP, which is critical for certificate validation, token expiry, and log correlation across the internet.