8 ms·
The Illustrated TLS 1.3 Connection
- thayne 4y agoIt's amazing how much overhead there is in the handshake just for backwards compatibility with previous versions.
- syncsynchalt 4y agoEvery one of them is traceable to working around some broken hardware or software out there that insists on everything looking like TLS 1.2. The good news is that TLS 1.3 moves everything possible into encrypted data, so in future versions spectators will not be able to see protocol differences and more compatibility hacks won’t be needed.
- tialaramex 4y agoHuh, it seems xargs.org is the new name for ulfheim.net ? Presumably the author fancied a change? At first I thought this might be a hijack or a rip-off, but everything checks out. For what it's worth, I don't recommend name changes. Obviously live your own life, but changing your name is a lasting inconvenience (ask any married western woman who made the mistake of saying "Yeah I'll take his name") and the rewards seem very thin.
- pabs3 4y agoInteresting quote from the site, I wonder how common this is in the age of open source: > Almost everything I've done professionally is behind the wall of private intellectual property. It's an odd thing to spend decades doing work that you're proud of, but having nothing to show for it.
- alfu 4y agoI thought of ulfheim too and it redirects to the new site. Author's reasoning: > A few years ago a hate group started using the "ulfheim" name for their own purposes. It's useless trying to reclaim a word, so I'm moving to the domain "http://xargs.org http://xargs.org". https://twitter.com/xargsnotbombs/status/1538227164599812096#m https://twitter.com/xargsnotbombs/status/1538227164599812096...
- syncsynchalt 4y agoYes, it’s still my site. I mirror all old hostnames across both domains but new sites will only have the xargs hostname most likely. It bothered me that anyone wondering about the domain would likely do a search on the word and end up at the list of SPLC hate groups. My choice was to add a disclaimer to everything I publish or just change domain names. I went with the latter.
- jborean93 4y agoThanks for making this wonderful resource. It’s been invaluable for me to understand the protocol itself. I’m sorry to hear the original name was hijacked by a hate group and you had to go out of your way to avoid such things.
- syncsynchalt 4y agoGlad to hear it was helpful!
- MrRadar 4y agoAs noted in the header, there are also versions of this for TLS 1.2, DTLS 1.3, and QUIC: https://tls12.xargs.org/ https://tls12.xargs.org/ https://dtls.xargs.org/ https://dtls.xargs.org/ https://quic.xargs.org/ https://quic.xargs.org/
- syncsynchalt 4y agoI don’t have it linked in the header but I’m also proud of https://curves.xargs.org https://curves.xargs.org, a visual explainer that (hopes to) give you an understanding of elliptic curve key exchange (ECDHE).
- smoldesu 4y agoThat's really slick, one of my favorite animated diagrams is the generic Fast Fourier Transform animation, and this definitely scratches that same itch. As someone who's horribly bad at math and visualizing this stuff, thank you!
- DethNinja 4y agoAre there any corporate MITMs that can handle TLS 1.3 regardless of the client executable? It looks like TLS 1.3 will eliminate the capture of encrypted malware communications. I’m assuming that most of the corporations will ban use of TLS 1.3 which is somewhat problematic for the future of such a core protocol.
- mcny 4y agoThis has been argued to death. Previously, on HN: https://news.ycombinator.com/item?id=12641880 https://news.ycombinator.com/item?id=12641880 > You're a bit late to the party. We're metaphorically speaking at the stage of emptying the ash trays and hunting for the not quite empty beer cans. > I agree, this isn't a low margin business either. We are talking about inferior security for all internet users for the sake of Well Fargo's quarterly report. > most of the corporations will ban use of TLS 1.3 literally one employee at one bank Wells Fargo said anything about it, after all was said and done. If the future of TLS depends on these idiots, we are all doomed anyway.
- deleted 4y ago[deleted]
- FreakLegion 4y agoYes, TLS 1.3 decryption is now supported in most of the tooling these companies use. The most widely deployed enterprise firewall for example added it a couple years ago[1]. The linked thread in the other reply to your question is 6 years old and the issues have basically been resolved. 1. https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/decryption-concepts/tlsv13-ssl-decryption-support https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/d...
- tialaramex 4y agoNote that this (and similar technologies from other vendors) is actually just a proxy. There is no "Man in the middle" in the cryptographic sense, the user has decided (or been forced by corporate policy) to allow their communications to be snooped by the proxy. If you go look at the certificate chains in your browser, you'll see that yup, instead of a public CA you're trusting Palo Alto Networks Inc. or whoever to "verify" that you're really talking to news.ycombinator.com
- deleted 4y ago[deleted]