
Meta’s public time service now uses Network Time Security (NTS), the RFC 8915 standard. The company said it made the change because conventional NTP can be vulnerable to spoofed time sources and man-in-the-middle attacks.
Developed in 1985, NTP does not provide built-in authentication for responses. A client may therefore accept an incorrect time from a spoofed server. That can disrupt certificate checks, credential expiry checks and the ordering of events in logs.
NTS uses TLS 1.3 to establish keys and then authenticates time packets. Meta says this approach reduces the risk of forged or replayed responses.
Accurate time synchronisation is increasingly important for automated certificate renewal. Certificate lifetimes are due to fall to 47 days by March 2029, while domain revalidation intervals are set to shrink to 10 days. Meta has published its timekeeping work on GitHub.
