3 ms·
It seems nice to have both layers. mTLS is great, but you're still exposing your TLS stack to the attacker. Dropping the packet altogether seems nicer.
by staticassertion 5y ago
It seems nice to have both layers. mTLS is great, but you're still exposing your TLS stack to the attacker. Dropping the packet altogether seems nicer.
- halpert 5y agoIn a perfect world, yes. What I’ve found in practice is that network policies add a mysterious failure point that makes debugging traffic issues hard, especially when providing a service platform to teams that don’t understand the inner workings. TLS failures tend to be easier to grok for most service devs.