Qubit Guard

The IETF just standardized the exact post-quantum key exchange already running in your browser — and Cloudflare’s own data shows most servers on the internet still don’t know they support it.

RFC 10024, published August 10, 2026, formalizes three hybrid mechanisms for TLS 1.3, pairing ML-KEM (FIPS 203) with classical elliptic curve exchange so a break in either the lattice math or the curve math alone doesn’t break the session:

The standard: X25519MLKEM768 is now Recommended (the other two, SecP256r1MLKEM768 and SecP384r1MLKEM1024, are not) — the mechanism browsers and servers should default to going forward.

The performance problem: Cloudflare’s September 8 “Automatic Key Exchange” rollout found that blindly defaulting to X25519 for origin connections was wasting a full extra round trip — HelloRetryRequest rates ran as high as 52% among scanned origins. Probing first and leading with the strongest supported algorithm cut that to 3.7% and improved P90 handshake latency by 150+ ms.

The adoption gap: ~33% of scanned origins now prefer X25519MLKEM768 and PQ traffic hit 45 billion connections/day — but only ~12.8% of individual origins support post-quantum key agreement at all.

Bottom line: RFC 10024 removes the “the standard isn’t finalized yet” excuse. X25519MLKEM768 is production-grade, Recommended, and already shipping in Chrome and Firefox. What’s left is knowing, server by server and load balancer by load balancer, what your own edge actually negotiates versus what you think you configured. That gap is exactly where audits find surprises.

QuantVision’s wire-layer discovery exists for this: it observes live network traffic to show which key exchange and signature algorithms your systems are actually using, not just what’s configured, across cloud, on-prem, or air-gapped environments.

When did you last verify which key exchange algorithm your public-facing TLS endpoints actually negotiate, not which ones you configured?

#PostQuantumCryptography #PQC #TLS #CryptoAgility #CISO #Cybersecurity #NIST #QuantumSafe #InfoSec #TechLeadership

Sources:
– RFC 10024 (IETF/RFC Editor): https://www.google.com/url?q=https://www.rfc-editor.org/info/rfc10024/&source=gmail&ust=1790856181119000&sa=E
– Cloudflare, “Automatic Key Exchange: faster, post-quantum secure origin handshakes” (Sept 8, 2026): https://www.google.com/url?q=https://blog.cloudflare.com/automatic-key-exchange-for-origins/&source=gmail&ust=1790856181119000&sa=E
– Datatracker record: https://www.google.com/url?q=https://datatracker.ietf.org/doc/rfc10024/&source=gmail&ust=1790856181119000&sa=E

Leave a Reply

You must be logged in to post a comment.

Qubit Guard messenger is helping businesses and larger networks that manage huge user base by providing a clear structure of conversations

Qubit Guard messenger is helping businesses and larger networks that manage huge user base by providing a clear structure of conversations