🔒Cloudflare Cuts TLS Handshake Latency by 150ms with Automatic Key Exchange
Cloudflare's TLS fix slashes handshake time by 150ms
TL;DR
Cloudflare's Automatic Key Exchange reduces TLS handshake latency by over 150ms, cutting HelloRetryRequests from 52% to 3.7%. Post-quantum security is now enabled for hundreds of thousands of domains.
Cloudflare's Automatic Key Exchange slashes TLS handshake latency by over 150ms at the 90th percentile, reducing HelloRetryRequests from 52% to 3.7%. This matters for anyone running a web server, as it cuts unnecessary latency and improves performance. The rollout now enables post-quantum security for hundreds of thousands of domains, with no configuration needed. Cloudflare is aiming to make the internet quantum-secure by 2029.

Key Points
Cloudflare's Automatic Key Exchange cuts HelloRetryRequests from 52% to 3.7%, reducing handshake latency by over 150ms at p90.
Post-quantum security is now enabled for hundreds of thousands of domains, with no configuration needed.
Cloudflare's scanning pipeline measures key agreement capabilities of each origin server, determining the preferred algorithm.
The percentage of origins supporting post-quantum key exchange algorithms grew from 0.5% to 12.8% between 2023 and today.
Cloudflare aims to make the internet quantum-secure by 2029, the year some experts estimate classical encryption could be breached.
Why It Matters
If you're running a web server, Automatic Key Exchange cuts unnecessary TLS handshake latency by over 150ms at p90, improving performance. Post-quantum security is now enabled for hundreds of thousands of domains, with no configuration needed. Cloudflare's goal is to make the internet quantum-secure by 2029, ensuring long-term security.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,482 builders reading daily.