Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)
- ID
- 22386
- Status
- summarized
- Published
- 08 Sep 2026, 9:10 PM
- Fetched
- 08 Sep 2026, 11:20 PM
- Provider
- Cloudflare Blog
- Category
- infrastructure
- Original URL
- https://blog.cloudflare.com/automatic-key-exchange-for-origins/
- Source URL
- https://blog.cloudflare.com/rss/
Summary
- Score
- 6.5
- Created
- 08 Sep 2026, 11:20 PM
- Tags
- Audience
- developerssaas_founders
What happened
Cloudflare replaced its static guess of X25519 for every TLS 1.3 origin connection with Automatic Key Exchange, which probes each origin to learn its preferred key agreement algorithm and leads with the post-quantum hybrid X25519MLKEM768 where supported. HelloRetryRequests dropped from ~52% to 3.7%, cutting 150+ ms at p90, and hundreds of thousands of domains now have post-quantum origin connections with zero configuration. Cloudflare is targeting a quantum-secure internet by 2029 ('Q-Day').
Why it matters
If your site is behind Cloudflare, you now get post-quantum origin encryption and faster handshakes automatically—no config change needed. If you run your own origin infrastructure without Cloudflare, this is a concrete benchmark for why you should start planning your post-quantum TLS migration now rather than waiting, since harvest-now-decrypt-later attacks are already in play.
Discussion angle
How much should builders care about post-quantum TLS today versus 2029—and does Cloudflare making it automatic change the calculus for choosing a CDN versus self-hosting origins?