3 ms·
This is a great write up. Also, for those saying that TLS is a panacea: encrypting and/or HMAC'ing all TCP data in and out of a box is operationally ridiculous
by packetized 11y ago
This is a great write up.
Also, for those saying that TLS is a panacea: encrypting and/or HMAC'ing all TCP data in and out of a box is operationally ridiculous unless you're in some sort of ultra high security environment.
- ajross 11y agoSorry, what's ridiculous about it? It's a very achievable thing. On modern CPUs with instruction support, AES encryption can be done faster than DRAM bandwidth. There are definitely latency costs in connection setup that will penalize "transaction-like" protocols I guess. It's not 100% free, but relative to the other performance issues you're looking at it's surely way way way down the list of priorities.
- packetized 11y agoPlease note my use of the word 'operationally'.
- ajross 11y agoHow does that change things? What's "operationally" ridiculous about it?
- packetized 11y agoThe overhead involved in piling on encryption management in an environment that doesn't specifically warrant it is a waste of resources.