Chrome plans to gradually roll out support for MTCs trusted by default in Chrome in early 2027, with current Certificate Transparency log operators leading the way. The final milestone for 2027 will hopefully result in MTCs usable in Chrome being widely available from multiple CAs. But Chrome’s PQ transition isn’t over at that point – offering MTCs isn’t enough to protect our users from an attacker with a quantum computer, ideally no matter what site they’re talking to. So how do we get there? In this talk, I’ll talk through Chrome’s plans and timelines for moving to an MTC-only web, covering what that means for the sites, CAs, and CT logs of today.
Speaker
Joe DeBlasio leads Chrome’s Networking Security team, which works on engineering, spec work, and policy for Merkle Tree Certificates, Certificate Transparency, the Chrome Root Program, BoringSSL, and TLS more broadly. He holds a PhD in network security measurement from UC San Diego, and has a core belief that dogs are, in fact, good. Cats are good too.