SECURITY Signal 386
Cloudflare Cuts Handshake Retries from 52% to 3.7% by Measuring Origin TLS Preferences
Cloudflare has replaced its static X25519 guess for origin TLS handshakes with per-origin measurement, cutting HelloRetryRequests on scanned origins fell from roughly 52% to 3.7%, removing over 150 ms from p90 latency.
This change significantly improves the efficiency of TLS handshakes, reducing latency and enhancing performance for a majority of connections. As more origins adopt post-quantum key exchanges, the reduction in handshake retries can lead to faster, more secure connections across the internet.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Cloudflare's new method reduces handshake retries dramatically, improving latency.
By measuring rather than guessing TLS preferences, it optimizes connection speed for many origins.
Post-quantum key exchange support is growing, but many origins still rely on classical methods.
THE CLUSTER
↗