2 ms·
You are correct that renegotiation has been a very rich source of bugs over the years. It has been removed in TLS 1.3. You would have to ask people who were in
by agl 10y ago
You are correct that renegotiation has been a very rich source of bugs over the years. It has been removed in TLS 1.3.
You would have to ask people who were involved in the early days of SSL to be sure but my impression was that the motivation was centered around the idea that symmetric keys should not be used to encrypt too much information. Thus extra handshakes were thought to be needed in order to "refresh" keys.
That's not inaccurate, although I feel that people wanted to rotate keys out of a sense of unease, rather than based on an analysis of how the security bounds change as the amount of data increases.
Server-gated crypto was certainly a reason, as detailed in a comment here by geofft.
These days (and I don't know if this was in mind when renegotiation was designed), renegotiation in HTTPS is almost exclusively used by servers (often IIS) to request a client-certificate after receiving an HTTP request.
There are much simpler ways to achieve these goals and they have been implemented in TLS 1.3 to replace renegotiation. I think that people were much more confident in their ability to write correct software in the 1990s.