Decoding the world of cybersecurity

Cloudflare exposes post-quantum TLS adoption gap

New Cloudflare telemetry will let customers inspect post-quantum TLS negotiation by connection, exposing a sizeable gap between browser-side adoption and encryption on connections to origin infrastructure.

Cloudflare exposes post-quantum TLS adoption gap
Summary
  • Cloudflare customers can now inspect negotiated post-quantum key exchange through analytics and logging products.
  • Cloudflare says about 70% of browser-generated traffic reaching its network uses hybrid post-quantum encryption.
  • Only around 15% of the origins Cloudflare connects to currently use the same hybrid approach.

Cloudflare has added connection-level visibility into post-quantum TLS, giving customers a way to see whether live traffic is actually negotiating quantum-resistant key exchange rather than relying on broad Internet adoption figures.

The new telemetry is being added to Logpush, Log Explorer, and HTTP Traffic Analytics. Cloudflare says customers can inspect the key-exchange algorithm negotiated on incoming requests, graph adoption, and identify domains or traffic paths that are still using classical cryptography.

The launch exposes a marked difference between the two sides of the company’s network. Cloudflare says roughly 70% of browser-generated traffic reaching its edge now uses hybrid ML-KEM post-quantum encryption, while only around 15% of origin servers that Cloudflare connects to use the same hybrid approach.

Those figures are Cloudflare’s measurements rather than a complete view of the Internet, but they illustrate the uneven nature of cryptographic migration. Browser vendors and large edge networks can roll out support relatively quickly across centrally controlled software and infrastructure. Origin environments are more fragmented, spanning different server stacks, libraries, load balancers, appliances, hosting models, and update cycles.

Hybrid key exchange combines a conventional algorithm with a post-quantum mechanism so that an attacker would need to defeat both to recover the shared secret. The approach is intended to provide protection against future cryptanalytic advances without abandoning currently trusted classical cryptography during the migration period.

The operational challenge is less about whether an organisation has heard of post-quantum cryptography and more about whether it can identify where existing cryptography is actually used. TLS termination can occur at browsers, content-delivery networks, reverse proxies, application gateways, load balancers, origin servers, and service-to-service connections. A high-level policy saying that post-quantum migration is under way does not establish which of those connections have changed.

Cloudflare’s new logging is designed to make that difference observable for traffic passing through its platform. That turns post-quantum readiness into something closer to an exposure-management problem: organisations can compare intended cryptographic posture with what connections negotiate in production.

The visibility will become more useful as regulatory, customer, and procurement expectations begin attaching dates to migration programmes. Cryptographic transitions tend to be long-lived because algorithms are embedded not only in software but in certificates, protocols, hardware, supplier products, and systems that may remain in production for years.

Cloudflare itself is targeting 2029 for full post-quantum security across its environment. The company has already enabled hybrid post-quantum encryption across several parts of its platform and has separately announced plans for a public certificate authority that would eventually support post-quantum certificate designs.

Those initiatives address different layers of the same transition. New algorithms are useful only if operators can determine where they are deployed, where classical cryptography remains, and which systems prevent migration. The large gap Cloudflare reports between browser traffic and origin connections suggests that the harder work may sit behind the edge, in the heterogeneous infrastructure organisations control less uniformly.

×