Cloudflare and Signal Are Already Quantum-Safe: Is Your Organisation?

Started by Sienna74, Jun 26, 2026, 01:40 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Cloudflare and Signal Are Already Quantum-Safe: Is Your Organisation?   Views(Read 82 times)

Sienna74

IBM's Q-Day article from yesterday features two companies whose behaviour is more instructive than any timeline prediction. Cloudflare started preparing for post-quantum cryptography in 2017. Signal has implemented post-quantum cryptographic protocols in its messaging. These are not quantum computing companies. They are infrastructure companies that looked at the threat landscape and concluded that waiting was more dangerous than preparing early.

Cloudflare's motivation is scale. A quarter of internet traffic flows through them. Upgrading their cryptography means upgrading the default security of a significant portion of the internet. They couldn't wait for Q-Day to be officially declared because by then the damage to the traffic they handle would already be in progress.

Signal's motivation is confidentiality. Messages that need to remain private for years into the future are vulnerable to harvest now decrypt later. Their users include journalists activists and people in authoritarian states whose communications could be harvested today and decrypted later. The threat is present for Signal users in ways that justify the engineering investment now.

What do these examples tell organisations that aren't Cloudflare or Signal? That the migration is achievable, the technology is available and the planning horizon is now not later.


GlassKnight35

Cloudflare beginning post-quantum preparation in 2017 when NIST had just issued its call is the timeline that puts most enterprises to shame. Nine years of preparation versus zero
Opinions are my own. Obviously.

Ava_75

Signal's user base includes exactly the people most at risk from harvest now decrypt later. Their implementation isn't theoretical it's protecting real people in real danger

Dank15

The migration being achievable is the most important point. This is not waiting for technology that doesn't exist. NIST published standards. Implementations exist. It's engineering and planning

QuantumToken98

Every organisation should ask what data they hold that a nation-state would want to read in ten years. That's the dataset to protect with quantum-safe cryptography first

CacheLayerSquid

Cloudflare's framing of wanting to upgrade cryptography for the whole internet not just their own stack is the right ambition for infrastructure companies

Joanne94

The gap between Cloudflare and Signal having done this and most enterprises not having started is the readiness gap in concrete form

GoalMachine

IBM Quantum Safe offering migration tools and consulting is the commercial angle behind this article. Useful to acknowledge but doesn't make the underlying argument wrong

Dank15

The Signal implementation being open source means the code can be audited. That transparency is the gold standard for security implementation

Related Topics (1)

Save money on everyday spending Free cashback on thousands of retailers
View offer