Lava lamps
– Cloudflare

Cloudflare brought forward its post-quantum timeline, setting a 2029 deadline to secure its platform against quantum threats, including authentication systems. The move reflects growing concern that advances in quantum computing could arrive sooner than expected, putting widely used cryptographic systems at risk.

Cloudflare has deployed post-quantum encryption across much of its network to mitigate so-called “harvest now, decrypt later” threats. Cloudflare now sees authentication as the more urgent vulnerability, as new research suggests attackers could exploit quantum capabilities to forge credentials and gain direct access to systems.

“What’s changed is the perceived timeline,” Bas Westerbaan, principal researcher at Cloudflare, explained “If Q-Day is far away, the main risk is ‘harvest now, decrypt later,’ so encryption naturally comes first. But recent advances, most notably those of Google and Oratomic, have accelerated the Q-day timeline, making protection against authentication attacks much more critical.”

Recent developments include a reported breakthrough in quantum algorithms targeting elliptic curve cryptography, as well as new resource estimates suggesting RSA-2048 and P-256 could be broken with fewer qubits than previously thought. Together, these advances have prompted a reassessment of how soon cryptographically relevant quantum computers could emerge.

Cloudflare argues that while data decryption risks remain significant, compromised authentication systems would be more immediately damaging. An attacker capable of forging credentials could impersonate trusted systems or gain persistent access through a single unprotected key.

“Where ‘harvest now, decrypt later’ requires attackers to find valuable information in a haystack, authentication is more akin to a castle with many doors,” Westerbaan noted. “Forget to upgrade one door to PQ, and an attacker gets in.”

The company plans to extend post-quantum protections across its entire product suite by 2029, with intermediate milestones beginning this year. These include adding post-quantum authentication support to origin connections, followed by broader rollout across customer-facing services and its secure access service edge (SASE) platform.

Deploying post-quantum authentication at scale presents significant challenges. Unlike encryption upgrades that can often be implemented as a single change, authentication requires coordinated updates across clients, servers, and certificate authorities, along with safeguards to prevent fallback to vulnerable methods.

“The more fundamental problem is that any authentication migration isn’t a single update,” Westerbaan explained. “It requires several steps … and coordinating all these changes across an entire ecosystem. Together, this can take years.”

Cloudflare emphasized that its 2029 target is not a prediction of when “Q-day” will occur, but a deadline for readiness amid increasing uncertainty.

“We don’t treat 2029 as a prediction of when Q-day will happen,” Westerbaan noted. “It’s the deadline to be ready by. … If the timeline is getting tighter, starting early is the only way to avoid being caught unprepared.”