Cloudflare details quantum downgrade attacks on IPsec, ships IETF mitigation in beta
matthew_d_green · x · 2026-09-30
Cloudflare revealed that a sophisticated attacker with a quantum computer could exploit a protocol design flaw to downgrade post-quantum IPsec tunnels back to classical crypto.
- The team worked with the IETF on a transcript authentication extension to block these downgrade attacks
- The mitigation is now in beta across Cloudflare's IPsec products
- The post explains that backward compatibility during the PQ migration window creates the downgrade risk
- Cryptographer Christopher Patton also urges practitioners to audit deployed key exchange protocols for similar bugs
More from Safety
- UK town fights 850-acre AI datacentre plan, rebuts Osborne's nimby charge — nordicinst · 2026-09-30
- CSET Report: AI Chip Smuggling Undermines Export Controls, Can Location Verification Help? — chrisrohlf · 2026-09-30
- Bill Gates calls for a new "AI Tax," mocked as a "damage generator" — markjeffrey · 2026-09-30
- DraftKings Is Using AI to Behaviorally Target Chronic Gamblers — paimapi · 2026-09-30
- Alaska woman turns herself in after Google AI Overview led her to hunt 3 birds out of season — Polymarket · 2026-09-30
- 0sec-labs open-sources 0: a self-evolving LLM harness for autonomous pentesting — udmrzn · 2026-09-30