Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why would TLS add an insecure by default feature? Hasn't security been a problem for TLS historically?

Or is this aimed at higher end providers that can be trusted to only enable it for certain things? (Like, Google Search might benefit from it, and replays probably aren't an issue?)



Because Google said they'd abandon TLS and use QUIC-CRYPTO unless TLS had 0-RTT in the core standard. And that they insist on splicing the early data onto the TLS stream, smearing H2 traffic across both.

Maybe they're right and it'll all be fine—but I expect named bugs in the same family as Triple Handshake.


0-RTT is not automatically enabled. You need to opt in.


Like if you're a CloudFlare customer? https://blog.cloudflare.com/introducing-0-rtt/ They enable it for TLS 1.3 by default for "GET requests with no query parameters" and place at least some of the onus on the origin server to detect replays (via a "Cf-0rtt-Unique" HTTP header).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: