Trending: On-device modelsSearch
iHeartGeek
iTECH

Cloudflare hardens IPsec against quantum downgrade attacks

The company has shipped beta support for an IETF extension that stops an on-path attacker stripping post-quantum encryption out of an IPsec tunnel before the endpoints ever notice.

Cloudflare illustration of an orange shield carrying a glowing atom-like orbit motif, resting on a tilted white card and ringed by pale orange concentric orbital lines on a white background

Cloudflare has helped the IETF develop a defence against a specific quantum-era attack on IPsec, and has implemented it in beta across its IPsec products. The extension adds a downgrade protection mechanism to the protocol, and customers on Cloudflare WAN and Magic Transit can switch it on by asking their account team to enable the ipsec_downgrade_protection flag.

The target is not the cryptography itself but the negotiation around it. IPsec endpoints agree on parameters during the IKEv2 handshake, and because the protocol keeps supporting classical algorithms for backwards compatibility, an attacker sitting on the network path can rewrite the opening messages so that each side believes the other is incapable of post-quantum cryptography. The tunnel then quietly falls back to classical Diffie-Hellman, which an attacker with a quantum computer can break.

Cloudflare is careful about the practical risk. Pulling the attack off requires a quantum computation to be performed live, during the handshake, rather than offline in the harvest-now-decrypt-later style that worries most security teams, and the company says it does not yet know whether or when such a machine will exist. Its argument is that shipping the new algorithms is not enough on its own: if an active attacker can force a fallback, the whole migration is pointless. Both ends of a connection have to support the extension for it to hold.

Why IPsec is the awkward one

IPsec sits below TLS and QUIC at the IP layer, so it props up site-to-site tunnels, VPNs and cloud interconnects rather than web pages. Cloudflare notes a second wrinkle in IKEv2: each party signs only the messages it sends, not the full handshake transcript as TLS 1.3 does, so a responder never confirms which initiator identity it actually accepted. A paper from 2016 showed that gap enables an identity-misbinding attack, where both endpoints end up using a key the attacker knows while one of them has authenticated the wrong peer.

The beta lands in the middle of a broader push. Cloudflare is targeting fully post-quantum security by 2029, has made post-quantum encryption the default across many products, and already publishes adoption figures through Cloudflare Radar, where roughly 70 per cent of browser traffic reaching its network uses hybrid ML-KEM while only about 15 per cent of the origins it connects to do. NIST has told the industry to retire RSA and elliptic-curve cryptography by 2030, which is the deadline many of those customers are working back from.

Our opinion

This is the least glamorous corner of the post-quantum story and arguably the most important. The industry has spent years adding post-quantum key exchange to protocols and treating that as job done, while the far messier problem sits in the negotiation layer, where backward compatibility is a feature until somebody hostile uses it as a lever. A downgrade attack needs a quantum computer working in real time, which is why nobody is panicking, but the fix costs almost nothing today and becomes impossible to retrofit once the hardware arrives.

The caveat is that Cloudflare's protection is only as good as the other end of the tunnel. Extensions to IPsec need both peers to opt in, and most of the internet's IPsec estate was configured years ago and is never revisited. Cloudflare can only guarantee the half it controls, so the sensible reading is that the company has built the mechanism and handed the awkward conversation to everyone running the far end.