Meta announced on October 6, 2026, that its public time service at nts.meta.com now supports Network Time Security (NTS), allowing devices to cryptographically verify time packets.
Stateless Architecture and Implementation
Meta stated that its NTS implementation operates across two phases: key establishment via NTS-KE over TLS 1.3, followed by authenticated NTPv4 over UDP. According to the company, the servers hold no per-client state.
Cookie keys are derived from a shared master secret and the current day rather than stored or replicated. This design allows the key exchange server and the downstream NTP servers to operate independently without sharing a session table.
Open Source Release and Mobile Gap
Meta announced it has open sourced the protocol, server, and client implementations through its Time library on GitHub. Oleg Obleukhov encouraged developers and platform maintainers to adopt NTS support.
While tools like chrony and ntpsec implement NTS, Meta noted that stock time clients on Android and iOS platforms still rely on unauthenticated UDP packets.
What to do
- Configure your NTP client using the chrony configuration line provided by Meta: pool nts.meta.com nts iburst maxsources 5.
Key facts and where they come from
- Meta's public time service now speaks NTS at nts.meta.com.
Meta’s public time service now speaks NTS (Network Time Security, RFC 8915) at nts.meta.com.
- Meta open sourced the protocol, server, and client on GitHub.
We’ve open sourced everything, including the protocol, server, client through Meta’s Time library on GitHub.
- Meta's NTS servers hold no per-client state and derive cookie keys.
Our NTS servers hold no per-client state. Cookie keys are derived, not stored and not replicated.
