Skip to content
Tag

TLS

Every article tagged TLS, newest first.

10 articles

Research

TLS 1.2 made servers refuse a resumption whose name had changed. TLS 1.3 removed that rule.

We have submitted a position paper to the IAB workshop on post-quantum authentication, and published the whole evidence base behind it: eleven CVE identifiers across eight pieces of software since 2014, reproductions against current OpenSSL, Go and nginx, a fourteen-host measurement of public endpoints, and what conforming would save a deployment that cannot safely resume today. It is a proposal, not a standard, and the page says so at the top.

6 min read
Research

Post-quantum makes session resumption essential. We are now measuring who offers it.

The PQC Observatory now records three things it never did: whether a host issues a TLS session ticket, whether it volunteers one without being asked, and whether it honours its own ticket when the ticket comes back. On the web panel today, 69 of 70 hosts issue a ticket, 40 of 70 send it without being asked for anything, and 61 of 69 resume. The gap between those first two numbers is the reason the measurement had to change.

7 min read
News

Post-quantum TLS 1.3 hybrid is now RFC 10024

The IETF has published RFC 10024, formally standardizing X25519MLKEM768, SecP256r1MLKEM768, and SecP384r1MLKEM1024 as hybrid post-quantum key agreement mechanisms for TLS 1.3. The three groups replace the long-running draft-ietf-tls-ecdhe-mlkem specification that browsers and libraries were already shipping as a de facto default. Here is what the RFC locks in, and what it still leaves for a separate migration.

4 min read
News

Cloudflare adds post-quantum authentication to origins

Cloudflare now supports post-quantum authentication between its edge and your origin server: Authenticated Origin Pulls and Custom Origin Trust Store both accept ML-DSA (FIPS 204) certificates. Paired with the X25519MLKEM768 key exchange already running on that hop, this is the first mainstream path to a fully post-quantum CDN-to-origin connection, not just the browser-to-edge leg.

3 min read
News

How much of the web already uses post-quantum TLS

By late 2025, around 43% of human web connections to Cloudflare were already using hybrid post-quantum key agreement, and X25519MLKEM768 is on by default in every major browser. The browser-to-edge hop is largely migrated. The unfinished half is origins, authentication, and your own stack. Here is where the line actually is.

3 min read
News

How ML-KEM became the browser default, release by release

Chrome has negotiated hybrid post-quantum key agreement by default since version 131 in November 2024, migrating from a pre-standard Kyber draft to the finalized X25519MLKEM768. The other major browsers and libraries followed. Here is how the switch happened, and what the hybrid does and does not protect.

3 min read
Research

Governments set the post-quantum deadlines. Their own sites are behind.

We added 201 government and public-sector sites to the PQC Observatory and measured them as their own panel. Just under a third negotiate post-quantum key exchange today. The pattern is not the one you would guess: several of the governments writing the migration mandates have not enabled it on their own front doors, while smaller states are already there.

4 min read
Research

The PQC Observatory: measuring post-quantum readiness across the web

Every month we probe a fixed panel of public hosts for hybrid key exchange and certificate posture, then publish the trend. Here is what the observatory measures, how, and why a vendor-neutral series is worth keeping.

2 min read
Research

We scanned 43 open-source projects for quantum risk. The bigger problem was classical.

We built a scanner to inventory quantum-vulnerable cryptography and ran it across 43 popular open-source projects. It flagged the RSA and elliptic-curve keys we expected and, more often than we'd like, TLS certificate verification switched off in production.

3 min read
Research

X-Wing and the TLS group: choosing a hybrid KEM combiner

Hybrid KEMs and hybrid signatures are not the same problem. For key exchange, the industry has largely converged on X25519MLKEM768, and there are good reasons to follow rather than invent.

3 min read
Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.