• Sources: Cloudflare blog, HN discussion
  • Summary: TLS 1.3 requires the client to commit to a key agreement algorithm in the first packet, and Cloudflare had guessed X25519 for every origin. Automatic Key Exchange replaces the guess with active scanning, a few single-group handshakes per TLS 1.3 origin across X25519, P-256, P-384, P-521 and X25519MLKEM768, weighted per subdomain by traffic volume and run outside the production path. Cloudflare reports HelloRetryRequests falling from roughly 52 percent to 3.7 percent, more than 150 ms off handshake latency at p90, and origin post-quantum support at 12.8 percent against 0.5 percent in 2023, all measured on its own network in a post dated 2026-09-08 that reached Hacker News on 2026-09-14.
  • Why it matters: An X25519MLKEM768 keyshare is 1,216 bytes against 32 for X25519, which pushes the ClientHello past one packet and is why the post-quantum group could not simply be the default, and Cloudflare states hundreds of thousands of domains now have post-quantum origin connections nobody configured.
  • Follow-up: Whether the origins that break on a post-quantum keyshare get fixed, because Cloudflare's earlier scan put that at about 0.34 percent and the scanner has to route around them.

send feedback on this story