MikhbarMIKHBAR
Apps & Software

Meta Introduces NTS Support for Public Time Service

Meta has upgraded its public time service to support Network Time Security (NTS), adding packet authentication and cryptographic verifiability to foundational network timing protocols.

Meta Introduces NTS Support for Public Time Service

Upgrading Internet Time With Cryptographic Authentication

Meta has announced that its public time service now speaks Network Time Security (NTS) at nts.meta.com. Under this update, packets are fully authenticated so that connecting devices can independently verify that the time data genuinely originated from Meta and was not modified in transit.

This rollout builds directly upon previous engineering efforts aimed at building a more accurate time service at Meta scale, which involved migrating infrastructure from ntpd to chrony, improving precision from 10 milliseconds to 100 microseconds, and opening time.meta.com to the public.

Why Network Time Security Matters Today

Traditional Network Time Protocol (NTP) has remained unauthenticated since 1985, functioning without explicit digital signatures or verified identity checks. While historical clock drift was once considered a minor operational annoyance, modern digital infrastructure relies heavily on accurate timestamps for critical security decisions.

Today, precise time is load-bearing across multiple core functions. Certificate validation compares notBefore and notAfter values against local clocks, token and credential expirations rely on correct timestamps, replay windows depend on accurate duration measurements, and proper log correlation requires synchronized chronologies.

These dependencies have grown even more pressing following shifts in industry certificate lifespans. As noted in CA/Browser Forum ballot SC-081v3, caps on publicly trusted TLS certificates continue to drop rapidly, moving automated renewal loops closer to a monthly schedule.

How NTS Operates in Two Distinct Phases

The NTS implementation functions across two distinct phases to ensure deployability. Phase 1 handles Key Establishment (NTS-KE) using TLS 1.3 over TCP port 4460, negotiated via ALPN ntske/1. During this phase, the client and server agree on an Authenticated Encryption with Associated Data (AEAD) algorithm and derive session keys directly from the TLS session.

Phase 2 executes Authenticated NTP using standard NTPv4 over UDP port 123 equipped with NTS extension fields. Forged packets fail verification and are dropped quietly without generating an NTS NAK, ensuring that failures remain completely indistinguishable from normal packet loss.

Stateless Server Architecture and Key Derivation

Meta's NTS servers maintain no per-client state. Cookie keys are dynamically derived rather than stored or replicated across a shared cluster. Servers compute sealing keys using a shared master secret combined with the current day measured in whole 24-hour periods since the Unix epoch.

This design completely eliminates the need for key rings, session tables, or complex distributed state synchronization mechanisms. The key exchange endpoint and the actual NTP responders operate as separate machines while remaining entirely resilient against state exhaustion attacks.

Open Source Availability and Community Adoption

Meta has open-sourced the entire protocol implementation, including the server and client components, making them freely available through Meta’s Time library on GitHub for developers and network administrators looking to secure their own time synchronization pipelines.

Furthermore, the engineering team is actively encouraging software maintainers, particularly those managing NTP clients on mobile operating systems like Android or iOS, to adopt NTS support and help secure the foundational time layer of the wider internet.

Sources

Continue chronologically

You are readingMeta Introduces NTS Support for Public Time Service
Emmys Move From Broadcast TV to Prime Video in 2027
Older storyEmmys Move From Broadcast TV to Prime Video in 2027October 6, 2026 · 3 min

Related entity coverage