Skip to content

Executive Summary

The organization is pursuing a maximalist stance for post-quantum (PQ) readiness, aiming for full readiness by 2029 to provide customers with future-proofed traffic protection. This goal requires three key objectives: helping product and engineering teams understand cryptographic usage and upgrades, providing progress metrics via counts of classical versus post-quantum cryptography usage, and surfacing prerequisites early regarding protocol and library support. To achieve this, the team developed an internal tool called CryptoLabe, which uses AI to discover cryptography in code, understand its use, and chart migration paths. The process involves a two-stage AI analysis: discovery mapping repositories for cryptographic elements and subsequent analysis investigating runtime usage and dependencies, culminating in classifications that categorize findings like classical encryption or PQ-ready hybrid key exchange. The system also identifies prerequisites (like missing ecosystem support) and hard cases (like custom protocols lacking standards) to guide migration planning.

Facts Only

* Cloudflare aims for a 2029 target deadline for full post-quantum readiness.
* The goal is to ensure customer traffic is future-proofed against quantum adversaries by adopting a "PQ everything!" stance.
* Three goals for the migration are: understanding cryptographic usage and upgrades, providing progress metrics, and surfacing prerequisites early.
* CryptoLabe is an internal tool designed to discover cryptography in code, understand its use, and chart migration paths.
* The discovery stage of CryptoLabe scans source, configuration, manifests, lockfiles, scripts, tests, and documentation for cryptographic elements.
* The analysis stage re-checks findings against source code and investigates runtime usage and dependencies across repositories.
* Findings are classified into categories such as Classical encryption, Classical signature, Classical token, PQ-ready hybrid key exchange, and PQ-ready.
* Prerequisites highlight blockers, such as dependencies on unmigrated standards or library support.
* Hard cases focus on custom protocols or cryptography built into hardware lacking ecosystem support.
* The system uses Cloudflare Workers and Durable Objects for orchestration, utilizing isolated sandboxes for code scanning.

Full Take

The narrative constructs a powerful argument for using advanced AI not just for pattern matching, but for complex, multi-layered contextual reasoning across massive, decentralized systems. The core tension lies between the scale of the problem (cryptography woven into vast codebases) and the practical difficulty of manual, exhaustive auditing. The structure moves from an aspirational goal to a concrete, albeit iterative, solution (CryptoLabe). The definition of "prerequisites" versus "hard cases" is a crucial analytical move; by segregating findings based on whether they are solvable by local teams (prerequisites) or require external coordination (hard cases), the system attempts to manage complexity. This approach implicitly recognizes that migration is less about a singular technical upgrade and more about coordinating a dependency chain across disparate software layers and external standards bodies. The reliance on iterative prompting and external validation underscores a necessary acknowledgment of epistemic uncertainty inherent in using AI for such foundational, high-stakes work. The implied challenge for any organization adopting this methodology is shifting focus from an exhaustive inventory (which is deemed impractical) to prioritizing system criticality based on dependency risks.
Bridge Questions: How can organizations systematically define the threshold between a "prerequisite" that requires immediate internal action and a "hard case" that demands external lobbying or ecosystem engagement? What metrics are most effective for measuring the ROI of surfacing prerequisites versus tracking hard cases? If AI-driven discovery is insufficient, what alternative human-centric verification loops can reliably validate the nuanced classifications assigned by the model?

From the original · Cloudflare Security

quantum migration As laboratories around the world race to build out a cryptographically relevant quantum computer, we at Cloudflare are racing towards a 2029 target deadline for full post-quantum readiness.
Read the full story at blog.cloudflare.com

Sentinel — Human

Confidence

The article presents a detailed narrative about developing an AI tool for post-quantum cryptography migration, demonstrating deep technical insight and strategic reasoning typical of expert communication.

Signals Detected
low severity: Natural variance in sentence structure and argumentation flow; use of domain-specific, yet accessible, technical explanations.
low severity: Strong, evolving argument built around a specific, complex problem (PQ migration) that transitions smoothly from corporate goals to methodological descriptions and final advice.
low severity: The structure follows a typical narrative arc: Problem -> Goal -> Method/Tool Development -> Methodology Deep Dive -> Conclusion/Advice, indicating intentional structuring beyond mere data regurgitation.
low severity: References to specific internal mechanisms (CryptoLabe architecture, Durable Objects, Workers AI) combined with high-level, non-trivial technical details suggest human expertise grounding the narrative, even if the exposition is polished.
Human Indicators
The text demonstrates a clear journey from setting a high-level vision ('PQ everything!') to detailing a complex internal engineering solution (CryptoLabe) and concluding with principle-based advice, which reflects genuine problem-solving thought rather than mere summarization.
Using AI to chart a course for our post | Huntaegis