Skip to content
NewTechnologyReported 2026-10-07 00:00

Meta Launches NTS for Verifiable Time Service

Meta has implemented Network Time Security (NTS) for its public time service, making time verifiable and authenticated. This addresses security concerns in certificate validation, token expiry, and log correlation.

//

What to watch

  • If the USD/JPY rate rises above 160 within the next 30 days, it would reflect a notable shift after Meta's NTS launch.

    Open

    By 2026-11-07 · Proposed by a model from the signal; a hypothesis until data decides it

  • If the EUR/USD rate climbs above 1.13 within the next 30 days, it would indicate a broader market reaction to the new time‑security service.

    Open

    By 2026-11-07 · Proposed by a model from the signal; a hypothesis until data decides it

Why it matters. Meta's NTS implementation enhances security for time-based protocols, affecting certificate validation, token management, and log correlation across the internet.

01

Who it touches

  1. 1Meta Platforms
  2. produces →Fact
    2MuseProduct
  3. invests in →Fact
    3Bug Bounty programOrganization
  4. part of →Fact
  5. uses →Fact
    5chronyTechnology
  6. enables →Fact
02

Evidence

  • MMeta Engineering BlogCompany2026-10-07 00:00
    Each server derives the sealing key from a shared master secret and the current day: key = HKDF-SHA256(master, salt = BE32(day), info = “fbnts-cookie-seal-v1”)
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    NTS support exists where you would expect it in the server world – chrony and ntpsec implement it.
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    Server-side, the public NTS list today runs to a few dozen entries, mostly national metrology institutes and internet infrastructure operators such as PTB, Netnod, and time.nl.
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    Each row’s session keys came out of its own TLS handshake and work only for that association.
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    Precision without authenticity only gets you a very accurate number from an unknown source. Now it can be both.
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    Cloudflare had launched time.cloudflare.com with NTS 15 months earlier, in June 2019, against the then-current draft, and showed it works at scale.
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    every one of them is trusting an unauthenticated UDP packet.
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    CLen 68 is the cookie: 36 bytes of envelope around the two 16-byte keys inside.
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    That indirection is why we use pool rather than server. A single server line gives you one association and one responder, which is a single point of failure – and NTP is a protocol that wants several sources so it can outvote a bad one. pool asks for maxsources independent assoc…
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    One line of chrony config: pool nts.meta.com nts iburst maxsources 5
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    Type 30 is the negotiated AEAD, AES-128-GCM-SIV, with KLen 128 bits of session key — chrony lists it first and client preference wins.
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    RFC 8915, Network Time Security for the Network Time Protocol, was published on the IETF Standards Track as a Proposed Standard in September 2020.
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    Phase 2 – Authenticated NTP: Standard NTPv4 over UDP/123 to the advertised server, with NTS extension fields.
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    Android’s platform time sync is plain SNTP over UDP/123 – a fixed 48-byte packet with no extension-field handling, alongside NITZ and GNSS – so there is no NTS path in it.
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    NTS works in phases, and separating them is what makes it deployable. Phase 1 – Key Establishment (NTS-KE): TLS 1.3 over TCP/4460, negotiated with ALPN ntske/1.
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    chrony runs perfectly well on Android
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    We’ve open sourced everything, including the protocol, server, client through Meta’s Time library on GitHub.
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    The key that seals them into a cookie is the shared one – the epoch day number from the derivation above, identical on every responder we run, stamped inside each cookie and never visible to the client.
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    Meta’s public time service now speaks NTS (Network Time Security, RFC 8915) at nts.meta.com.
    View source
  • MMeta Engineering BlogCompany2026-10-07 00:00
    We’ve previously written about building a more accurate time service at Meta scale – migrating from ntpd to chrony, going from 10 milliseconds to 100 microseconds, and opening time.meta.com to everyone.
    View source