The Web Is Preparing for Certificates That Can Survive Quantum Attacks

Cloudflare plans to issue quantum-proof TLS certificates, giving millions of websites a path toward encryption that can withstand future quantum attacks. The internet infrastructure provider will use an open source platform that issues both classic TLS certificates and Merkle Tree Certificates, then acquire a trusted certificate root from CA GlobalSign.
The goal is simple for website operators: move to post-quantum certificates at the flip of a switch without increased performance overhead. Cloudflare representative Steve Goldsmith said, “We are not issuing certificates yet, and it will be a little while before we do.” The plan still marks a major step in a WebPKI overhaul that will take years.
TLS certificates help websites prove their identity and protect information during web connections. Making that system safe for the post-quantum age requires changes to certificates, signatures, transparency logs, and the chain linking them together.
Why Merkle Trees Matter for Web Encryption
Quantum-proof versions of today’s classical X.509 certificates would add roughly 40 times the data for a TLS handshake. That extra size could make post-quantum protection difficult to deploy across the web, especially when every connection must carry certificate information before secure communication begins.
Google announced a solution involving Merkle Trees in February, reducing handshake data to about 40 kilobytes. In today’s WebPKI, a multi-link chain of quantum-vulnerable signatures confirms that a certificate can be trusted. Post-quantum systems replace that chain with Merkle Tree proofs.
Quantum-proof signatures can travel during web requests and enter transparency logs, creating a record that helps prevent counterfeit certificates. Transparency logs are separate from certificate issuance, but Merkle Tree Certificates couple the two processes. Cloudflare engineer Mari Galicer described the change this way: “By coupling issuance and logging, transparency becomes a requirement for operation, rather than an add-on.”
That connection changes how the system works. Instead of treating logging as a separate layer added after certificates are issued, the certificate process depends on transparency from the start. Cloudflare’s open source platform is designed to issue both the familiar classic certificates and the newer Merkle Tree Certificates.
A New RSA Attack Raises a Separate Warning
Quantum computing is not the only pressure facing public-key cryptography. A new RSA attack announced on Sep 24, 2026, reduces the security level of RSA to 2 65, 2 90, and 2 119 for 1024-, 2048-, and 4096-bit keys respectively.
The attack uses a variant of the number field sieve algorithm invented in 2007 against an oracle in RSA. Factoring a 1024-bit RSA key requires an estimated 2 80 operations and 500,000 to 1 million CPU core-years. Using the sieve to forge a signature took 2 65 operations and 1,380 core-years.
Those numbers drastically lower the estimated security of textbook RSA, but the attack poses little immediate practical threat. It requires more computation than most entities can achieve, except possibly nation-states or large companies.
There is another important limit: the attack works only against blind-signature implementations of RSA, such as textbook RSA. Most RSA implementations today use PKCS or PSS padding, which prevent the attack. That distinction keeps the result from becoming a general break of every RSA system in use.
Why the Quantum Risk Reaches Beyond Websites
Cryptographers are working to develop alternative cryptosystems resistant to quantum attacks, but replacing the web’s public-key infrastructure will take years. Cloudflare’s plan focuses on making the transition easier for websites by removing the need for each operator to rebuild its security setup alone.
The concern also reaches digital assets. An EU warning says $504 billion of Bitcoin is exposed to quantum threats. That figure places the certificate transition alongside a wider effort to protect systems that depend on cryptographic signatures.
Karsten Nohl, head of innovation at Allurity, and Nadia Heninger, a University of California at San Diego professor and lead author of the RSA research, are among the names connected with the broader cryptography discussion. The issues differ, but they point to the same challenge: security systems built for today’s computers must prepare for machines and attacks that demand new defenses.
Cloudflare’s planned certificates do not complete that work. They offer a practical piece of it, combining an open source issuance platform, a trusted root from CA GlobalSign, Merkle Tree proofs, and transparency logs. The larger change will take years, but the first steps are already being designed.
Based on




