3 ms·
This is indeed a cool feature. I hadn't been aware of it until now. I see that Dirk Balfanz from Google published a IETF draft a couple years ago. I need to di
by sweis 12y ago
This is indeed a cool feature. I hadn't been aware of it until now. I see that Dirk Balfanz from Google published a IETF draft a couple years ago.
I need to digest the security implications, but it seems like a nice mitigation to session theft.
- zobzu 12y agountil tls session resumption gets more common and someone comes up with a "tls session resumption is not in fact secure" :( there were some talks in 2013 about this in various sec conferences