Every time Cloudflare opens a new TLS 1.3 connection to an origin server, we have to make a guess: the protocol requires us to commit to a key agreement algorithm in the very first packet we send, before the origin has told us anything about itself or what it can support. If we guess right, the handshake completes in one round trip. Guess wrong, and the origin replies with a HelloRetryRequest , we start over, and the connection costs two round trips. For years, our guess was the same for every origin on the Internet: X25519 . Widely supported, but as it turns out, suboptimal for roughly 30% of the origin connections we've since measured. Today we're announcing Automatic Key Exchange , an extension of Automatic SSL/TLS that replaces the guess with a measurement.…