← Back to News

Cloudflare adds post-quantum origin authentication

2026-07-30 · cloudflare

Cloudflare has launched post-quantum authentication support for origin connections through Authenticated Origin Pulls and Custom Origin Trust Store. That matters because future quantum threats are not only about decrypting stored traffic later, but also about forging trust and impersonating systems that were once considered safe. For anyone thinking seriously about preservation, this is a reminder that archived data can outlive the cryptography protecting it. If identity, keys, and encrypted stores are not designed for long horizons, today’s retained data can become tomorrow’s compromised asset.


What Happened

Cloudflare announced support for post-quantum authentication when connecting to customer origin servers, calling it a first step toward broader post-quantum authentication across its products. The update is aimed at mutually authenticated TLS connections, pushing protection beyond confidentiality and into server identity and trust validation.

The Cost of Data Loss

If an attacker can eventually forge authentication or exploit aging trust models, backup copies and archived datasets become high-value targets rather than safe fallbacks. Long-retention data is especially exposed because its protection window is measured in years, not days, and recovery plans fail if the protected copies can no longer be trusted.

How Cold Storage Prevents This

Cold storage reduces exposure by keeping critical recovery material, master backups, and key artifacts offline and away from constantly reachable systems. When paired with disciplined key rotation and offline verification, it gives organizations a cleaner trust boundary for the data they may need most during a future cryptographic or operational failure.

Read Original Post →