Quantum computers could eventually break HTTPS, but Cloudflare has a plan

That little padlock in your web browser is supposed to tell you that your connection to a website is secure. The technology behind it works remarkably well today, but sufficiently powerful quantum computers could eventually create a serious problem for the encryption and authentication systems the web depends on.

Cloudflare is preparing for that possibility now. The company plans to become a public Certificate Authority, meaning it would issue the digital certificates websites use to prove their identity and establish secure HTTPS connections.

This isn’t simply Cloudflare launching another security product for its existing customers. A public Certificate Authority becomes part of the trust infrastructure of the web itself, putting Cloudflare alongside the relatively small group of organizations responsible for issuing certificates that browsers and operating systems recognize.

Cloudflare’s proposed CA will support conventional certificates alongside post-quantum Merkle Tree Certificates, or MTCs. The idea is to give websites a path toward quantum-resistant authentication without requiring site owners to suddenly replace everything when the threat becomes more immediate.

That last part is seriously important, because migrating the web away from vulnerable cryptography isn’t something that can happen overnight. There are billions of devices in use, including old smartphones, computers, smart TVs, and embedded hardware that may never receive another meaningful software update.

Cloudflare is trying to deal with that compatibility problem by acquiring publicly trusted Root CA key material from GlobalSign. A trusted root essentially tells browsers and operating systems which Certificate Authorities they should believe, and Cloudflare says the acquisition should help its certificates work with older hardware.

The company has also applied for inclusion in the root programs operated by Google Chrome, Apple, Microsoft, and Mozilla. Those applications still have to go through the respective approval processes, so Cloudflare can’t simply declare itself trusted across the web and call it a day.

The more interesting technology here is MTCs. Instead of sending bulky post-quantum signatures during every connection, the system uses lightweight proofs to verify that a certificate appears in a trusted registry. Cloudflare says this approach can provide post-quantum protection without sacrificing the speed people expect when loading websites.

Cloudflare plans to begin issuing traditional certificates after completing the necessary browser root program processes. Production issuance of Merkle Tree Certificates is scheduled to begin during the first quarter of 2027, while the GlobalSign transaction is expected to close within roughly two months, assuming the usual closing conditions are met.

None of this means quantum computers are about to break HTTPS tomorrow. Building a cryptographically relevant quantum computer remains an enormous technical challenge, and nobody knows exactly when, or even if, machines capable of defeating today’s widely deployed public-key cryptography will arrive.

Waiting until such a machine exists would be a terrible strategy, though. Internet infrastructure moves slowly, old devices stick around for years, and cryptographic migrations can involve browsers, operating systems, servers, standards bodies, certificate authorities, and website operators all moving in roughly the same direction.

Cloudflare CEO Matthew Prince describes upgrading web security before quantum computers can break it as one of the biggest coordination challenges in Internet history. There is some corporate drama in that description, but the underlying problem is real: HTTPS only works because an enormous collection of systems agree about whom and what to trust.

Cloudflare clearly wants a much bigger role in that trust chain. If its public CA and post-quantum certificate plans work as intended, website owners may barely notice the transition.

And that’s probably the best possible outcome. If quantum computers eventually become powerful enough to threaten today’s cryptography, the ideal time to protect the web isn’t the day after that happens. It’s years before.

☕

Support independent tech journalism

NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi.

Support NERDS.xyz
Written by

Brian Fagioli ✔

Technology journalist and founder of NERDS.xyz

Brian Fagioli is a technology journalist and founder of NERDS.xyz. A former BetaNews writer, he has spent over a decade covering Linux, hardware, software, cybersecurity, and AI with a no nonsense approach for real nerds.

Leave a Comment