
3/17/2025 · Sharon Goldberg, Wesley Evans, Bas Westerbaan, John Engates
What this post added
This post announces the first phase of end-to-end quantum readiness for Cloudflare's Zero Trust platform, enabling customers to protect corporate network traffic with post-quantum cryptography. It details the use of ML-KEM for key agreement in TLS 1.3 to protect against 'harvest now, decrypt later' attacks and secure internal applications via Cloudflare Tunnel, clientless Access, WARP device client, and Gateway. It also discusses the challenges of migrating away from RSA and ECC, the 'harvest now, decrypt later' threat, and the two-phase migration strategy focusing on key agreement first.