
The Cloudflare mTLS vulnerability - A Deep Dive Analysis
The Backend Engineering Show with Hussein Nasser
00:00
The Stateless Way to Encrypt a Session
The server and the client agree on actually two secrets. They are different secrets. The main resumption main secret is not used at all. So only the client actually stores the knowledge of this thing. Right? You can, you can also technically connect to another server and it'll be fine. How? Let's do this now. A new session is established. I want to resume a session. What do we do? We don't provide client certificate. We don't do any certificates or anything. It's literally just a data structure. And then encrypt that data structure with another key. That key must be known to the server and rotate it. But there is a key inside, inside
Transcript
Play full episode
Remember Everything You Learn from Podcasts
Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.