The Backend Engineering Show with Hussein Nasser cover image

The Cloudflare mTLS vulnerability - A Deep Dive Analysis

The Backend Engineering Show with Hussein Nasser

00:00

How to Decrypt a Session Ticket

All what the client does is they do a client hello and they send everything in the client hello. The second recession ticket inside the client hello says, Hey, hey, server, last time you remember you should give me that. I want to resume a session. And now we might say, like there is a main secret that's associated with that, the client knows, but the client never sends that secret on plain text. Right? But since this encrypted session, which is also pointless, even the client cannot declare that, but the server can. So the client, the server gets that session ticket, decrypts it, right? With that key, the key must exist in the server

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app