Lifestyle
Cloudflare now lets websites see how much of their traffic is protected against future quantum computers
On September 29, 2026, Cloudflare announced that website owners using its service can see, connection by connection, whether visitors' traffic uses post-quantum encryption, which is meant to resist decryption by future quantum computers. Here is what changed, why it matters and what it means for everyday internet users.
About 5 min read

What Cloudflare announced
On September 29, 2026, Cloudflare announced additional post-quantum (PQ) cryptography visibility tools in its Application Security and Logs products. Post-quantum cryptography means encryption designed to stay secure even against powerful quantum computers in the future. According to the company, customers can now view and chart how much of their live traffic uses post-quantum TLS 1.3 encryption in Logpush, Log Explorer (Cloudflare's logging tools) and the HTTP Traffic Analytics dashboard. They can also see the key exchange algorithm negotiated for each request. TLS is the standard that encrypts connections between a browser and a website, and the key exchange is the step in which both sides agree on the secret key used to encrypt that connection.
Cloudflare says it already showed which TLS version each domain used, but it had not previously shown the cryptographic algorithms used within TLS at the domain level. The new features include a TLS Key Exchange card in HTTP Traffic Analytics. Logs also gain a ClientTLSKeyExchangeGroup field for visitor-to-Cloudflare connections, and Logpush gains an OriginTLSKeyExchangeGroup field for Cloudflare-to-origin connections. An origin server is the website's own server that sits behind Cloudflare.
Read the full description
Sources are collected, independently checked, then reviewed by Jev.
Why post-quantum encryption matters now
As cited by Cloudflare, the US National Institute of Standards and Technology (NIST) stated in 2024 that RSA and elliptic curve cryptography (ECC), two widely used encryption methods, should be deprecated by 2030. Many governments and regulators have since backed that deadline. Cloudflare also notes that post-quantum encryption guards against "harvest now, decrypt later" attacks, in which attackers collect encrypted data today and decrypt it once powerful quantum computers arrive.
Cloudflare says its goal is to be fully post-quantum secure by 2029, while many customers are working toward quantum-readiness deadlines around 2030. According to aggregate Cloudflare Radar data, about 70% of browser traffic reaching Cloudflare uses hybrid ML-KEM (FIPS 203), but only about 15% of the origin servers it connects to do. Hybrid ML-KEM combines a classical method with a post-quantum one.
| Key exchange | Type | Cloudflare's description |
|---|---|---|
| X25519MLKEM768 | Hybrid post-quantum (TLS 1.3) | The only recommended post-quantum group in TLS 1.3; preferred by most major browsers |
| X25519, P-256, P-384 | Classical ECDHE | Still widely used across the internet, but offers no post-quantum protection |
| X25519Kyber768Draft00 | Early post-quantum draft | Deprecated; implemented before IETF standardization, still used by a small number of visitors |
| None | RSA key agreement or no TLS | RSA is quantum-vulnerable; seen with TLS 1.2 or earlier |
Cloudflare explains that X25519MLKEM768 runs two key exchanges and then combines the two shared secrets. One is a classical X25519 elliptic curve key exchange (ECDHE) and the other is post-quantum ML-KEM. The result is secure as long as either one is secure. The company also notes that TLS 1.2 and earlier versions do not offer post-quantum encryption.
What it means for everyday readers and site administrators
For everyday users, Cloudflare says most major browsers already prefer X25519MLKEM768. That means many connections may already be post-quantum encrypted when you browse sites that use the service with an up-to-date browser. Cloudflare says Chrome users can check which key agreement algorithm a page uses: right-click, choose "Inspect" and open the "Security" tab.
For site administrators using Cloudflare, the company says there is no separate post-quantum switch. Post-quantum encryption is negotiated automatically when TLS 1.3 is enabled and the visitor supports it. If most traffic still uses classical algorithms, Cloudflare suggests that many visitors may be non-browser clients that lack support. For legacy origin servers that are unlikely to support post-quantum cryptography, Cloudflare suggests placing them behind Cloudflare Tunnel so they connect over TLS 1.3 with X25519MLKEM768.
FAQ
What is a "harvest now, decrypt later" attack?
According to Cloudflare, attackers collect encrypted data now and decrypt it later, once powerful quantum computers exist. If data will still be valuable years from now, it needs post-quantum encryption today.
What exactly can the new features show?
Cloudflare says customers can see the key exchange algorithm negotiated by each connection in HTTP Traffic Analytics, Logpush and Log Explorer. Examples include X25519MLKEM768 or classical X25519 and P-256. This shows how much of a domain's traffic uses post-quantum encryption.
Do everyday internet users need to do anything?
Cloudflare says most major browsers already prefer X25519MLKEM768, so keeping your browser up to date is enough to benefit. Whether post-quantum encryption is used depends mainly on how websites and servers are configured.
Why does some site traffic still not use post-quantum encryption?
Cloudflare points to two possible reasons: the site may not have TLS 1.3 enabled, or many visitors may be non-browser clients that do not support X25519MLKEM768. TLS 1.2 and earlier do not offer post-quantum encryption at all.
What do the 2029 and 2030 dates each mean?
2029 is Cloudflare's own target for full post-quantum security. 2030 is, as cited by Cloudflare, the deadline NIST set in 2024 for deprecating RSA and ECC, and many customers' quantum-readiness deadlines fall around that time.
Browse the latest news in this topic
Lifestyle
Cloudflare open-sources Streamline: a demo of using its cloud services to add graphics to live streams and burn subtitles into videos
On October 2, 2026, Cloudflare launched and open-sourced Streamline, a developer playground showing how developers can combine Stream, Workers, Containers and Durable Objects to build their own video processing pipelines, such as adding graphics to live streams in real time or adding subtitles to videos. This article explains what it is, how it works, its limitations, and what it means for viewers and developers.
Lifestyle
Google unveils Gemini 4 Argon: cyber defenders get it first, everyone else still has to wait
On September 30, 2026, Google announced Gemini 4 Argon, which it calls its new frontier (most advanced) AI model. For now it is available only to trusted cyber defenders through the Fairwind Program. Here is what Google says the model can do, what it will cost developers, how Google says it is managing the risks, and what it means for everyday users. All figures come from Google itself.
Lifestyle
NVIDIA: CoreWeave Begins Offering Vera Rubin NVL72, With Cognition as First Production Customer
According to the NVIDIA blog, AI cloud provider CoreWeave now offers NVIDIA's next-generation Vera Rubin NVL72 systems, plans to offer the Vera CPU and launched CoreWeave Forge. This matters mainly to companies building AI agents, and could eventually mean faster AI tools for everyday users.
Lifestyle
Google Cloud makes Spanner Omni generally available: its Spanner database can now run in companies' own data centers and on other clouds
Google Cloud says Spanner Omni, a version of its Spanner database that businesses run themselves, is now ready for real-world use in their own data centers, on other clouds or on a laptop. This matters to organizations that want Spanner outside Google Cloud, but they take on the running of it. Here are the features, licences and trade-offs Google Cloud describes.
Latest travel guides

GuideTokyo
Where to Stay in Tokyo: Comparing Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza, Plus Airport Access, Accommodation Tax, and Luggage Delivery
Where should you stay in Tokyo? Compare Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza by the same criteria: access from Narita and Haneda, transit routes, nearby attractions, neighborhood character, and who each area suits. Includes a comparison table, a Yamanote Line diagram, Tokyo’s accommodation tax as verified in 2026/9 (changing to 3% in 2027/4), and Airport TA-Q-BIN luggage shipping rules.
- Budget
- Hotels

GuideTokyo
How to Choose Tokyo Transit Passes: Are Suica, Welcome Suica, the Tokyo Subway Ticket, and the JR Pass Worth It?
On a first Tokyo trip, start with an IC card and pay per ride (Welcome Suica has no deposit and is valid for 28 days). If you take four or more subway rides in a day, add a 72-hour Tokyo Subway Ticket for 2,000 yen; a JR Pass is never worthwhile if you stay in Tokyo and do not go to Kansai. See what TOURIST PASMO, Suica on iPhone, and the Tokyo Metro day pass do and do not cover, with a decision chart. Prices verified in September 2026.
- Transport
- Budget

GuideTokyo
Tokyo Disneyland and DisneySea Guide: Ticket Prices, Fantasy Springs, Disney Premier Access (DPA), Standby Pass, and Which Park to Choose for Your First Visit
Tokyo Disney one-day Passport prices vary: most weekdays in 9/2026 cost ¥9,900 and weekends ¥10,900. At 14:00 daily, tickets go on sale for the same date two months later. Free Priority Pass is no longer on the official service list; only paid Disney Premier Access (¥1,000–3,500 per person per use) shortens waits. Covers hours, the 25th anniversary, Standby Pass, Entry Request, Fantasy Springs access and first-visit park choice; checked on the official site in 9/2026.
- Itineraries
- Family