After years of hating running, this Garmin watch transformed me — and now it's cheaper than ever beforeBuilding resilient real-time streaming workers with Amazon DynamoDB leasesModel-agnostic PII detection with LLMsBest laptops 2026: Premium, budget, gaming, 2-in-1, and moreParagon Backup & Recovery Community Edition review: Free file-level backup? YesBoots on the Ground: ‘WARDOGS’ Goes All Out on GeForce NOW at Early-Access LaunchAfter years of hating running, this Garmin watch transformed me — and now it's cheaper than ever beforeBuilding resilient real-time streaming workers with Amazon DynamoDB leasesModel-agnostic PII detection with LLMsBest laptops 2026: Premium, budget, gaming, 2-in-1, and moreParagon Backup & Recovery Community Edition review: Free file-level backup? YesBoots on the Ground: ‘WARDOGS’ Goes All Out on GeForce NOW at Early-Access Launch
Pull down to refresh stories
Courses Write Login VIVietnamese Store

Post-quantum authentication to origins is now supported

Post-quantum authentication to origins is now supported should be explained through that lens before any broad claim is made. The real value of this story is that it touches operational safety, not just another settings layer.

Post-quantum authentication to origins is now supported

Post-quantum authentication to origins is now supported should be explained through that lens before any broad claim is made. Cloudflare's Authenticated Origin Pulls and Custom Origin Trust Store now support post-quantum authentication. Here we’ll explain how you can configure fully post-quantum secure mutually authenticated TLS connections to your origin server, dive into the engineering details of how we built it, make a shameful confession, and finally explain how this work fits into our overall post-quantum migration roadmap. The piece keeps the context, impact, and follow-up signals in view so readers do not stop at the headline.

What happened

Cloudflare's Authenticated Origin Pulls and Custom Origin Trust Store now support post-quantum authentication. The floor is firmer here because the story is anchored by an official source, not only by second-hand reaction. In security, the real value is whether the team becomes measurably safer, not whether another settings screen has been added.

Practical impact for readers

Here we’ll explain how you can configure fully post-quantum secure mutually authenticated TLS connections to your origin server, dive into the engineering details of how we built it, make a shameful confession, and finally explain how this work fits into our overall post-quantum migration roadmap. In security, the real value is whether the team becomes measurably safer, not whether another settings screen has been added. The people who should read carefully are system admins, shop owners, content teams, and anyone holding customer data or operational accounts.

Details worth verifying

Our focus for the past several years has been in deploying post-quantum encryption to protect against harvest-now/decrypt-later attacks, where an attacker quietly stockpiles your encrypted data with the hope of decrypting it in the future with a quantum computer. The people who should read carefully are system admins, shop owners, content teams, and anyone holding customer data or operational accounts. In security, the next follow-up is patch speed, real adoption, and whether teams actually keep the safer behavior in place.

Who should act or wait

However, recent breakthroughs in quantum computing and cryptanalysis pulled the timelines for upgrading to post-quantum cryptography forward across industry and government and have caused us to shift our attention to deploying post-quantum authentication , to protect against attackers who will soon be able to use quantum computers to break classical credentials and carry out impersonation attacks.

What is still unclear

In a previous post, we announced that Cloudflare is targeting 2029 for full post-quantum security, and laid out several milestones to hit along the way. We have reached the first of those milestones: our Authenticated Origin Pulls and Custom Origin Trust Store products now support post-quantum (PQ) authentication via Module-Lattice-Based Digital Signature Algorithm (ML-DSA) signatures to protect connections between Cloudflare and customer origin servers.

Source notes

Related stories

SecurityWindows 11’s next security feature may cost you gaming performanceSecurityEnterprise AI transformation relies on the end-to-end platform: Azure was built for this momentSecurityAI-driven development lifecycle using Amazon Bedrock AgentCore