Preventing quantum downgrade attacks against IPsec

Imported from official source

Cybersecurity Classified by Officially

For Birthday Week, Cloudflare is helping one of the Internet’s core security protocols develop stronger protections against quantum downgrade attacks. To protect our customers and the Internet at large, we worked with the IETF to develop a mitigation against downgrade attacks on IPsec, which we’ve implemented and made available in beta across our IPsec products.

The world is racing to build the first generation of quantum computers. These new machines hold great promise, but they also create a new threat: early quantum computers will be capable of cracking cryptography we've relied on for secure communication. To address this, it is necessary to migrate to post-quantum (PQ) cryptography: cryptography we believe even quantum computers cannot break. Diffie-Hellman key agreement will have to be replaced by PQ key agreement mechanisms such as ML-KEM; classical signature schemes, like ECDSA and RSA, will have to be replaced by PQ schemes such as ML-DSA; and so on.

The PQ migration is well underway, and we’re helping the migration along by making post-quantum encryption the default in our products, open-sourcing part of our internal cryptography discovery tool, launching new post-quantum visibility features, and leading the way in the web’s migration to post-quantum certificates. Still, it will take years before all clients and servers on the Internet have been upgraded to post-quantum cryptography. In the meantime, it will be necessary for modern devices to maintain support for classical cryptography in order to connect with today’s endpoints.

This is an extract. The publication continues at the source.

Read the original at the source: https://blog.cloudflare.com/ipsec-downgrade-protection/

Officially imported this from Cloudflare’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Cloudflare — imported from official source
Official source
https://blog.cloudflare.com/rss/ RSS
Imported
September 29, 2026 14:00
Versions
1 recorded
Identity
01KXDH1HXQQK6WKDPTP4HR9A2V

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.