Random Number Generation for Security
Cloudflare targets 2029 for full post-quantum security

Cloudflare targets 2029 for full post-quantum security

4/7/2026 · Bas Westerbaan

What this post added

This post announces an accelerated timeline for Cloudflare's post-quantum security roadmap, now targeting 2029 for full post-quantum security, including authentication. It highlights recent advancements in quantum computing research (Google's improved elliptic curve breaking algorithm, Oratomic's resource estimates for breaking RSA-2048 and P-256) that have pulled forward the estimated Q-Day. The post emphasizes the shift in industry focus from post-quantum encryption (mitigating harvest-now/decrypt-later attacks) to post-quantum authentication, as broken authentication is considered catastrophic. It discusses the prioritization of long-lived keys, the necessity of disabling quantum-vulnerable cryptography to prevent downgrade attacks, and the subsequent need to rotate secrets.

Read the original post ↗