Preventing quantum downgrade attacks against IPsec

Cloudflare Version 1 original current

Imported from official source

A sophisticated attacker with a quantum computer can exploit a protocol design flaw to downgrade post-quantum IPsec tunnels to classical crypto. We helped the IETF develop a transcript authentication extension to prevent these attacks.

This version

Version
1 of 1
Recorded
September 29, 2026 14:00
Change
Initial
Content hash
efc5e9b10d60ae27148d9df62b09accb
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.