Tech article
Cloudflare AKE cuts origin HelloRetryRequests from 52% to 3.7%
No preview is available. Read the original article for the full story.
Hacker News | Sep 14, 2026 | iamsyr
Automated excerpt
Automatic Key Exchange finds what your origin supports. If X25519MLKEM768 is unavailable, Cloudflare continues using a compatible classical key agreement and can still avoid unnecessary HelloRetryRequest round trips by learning which one your origin prefers. However, Automatic Key Exchange can only prefer post-quantum connections when your origin server already supports the key agreement algorithm. The connection between cloudflared and Cloudflare already uses post-quantum key agreement.
Selected automatically from source text; not independently written or fact-checked. Read the original for full context.