The Backend Engineering Show with Hussein Nasser cover image

The Cloudflare mTLS vulnerability - A Deep Dive Analysis

The Backend Engineering Show with Hussein Nasser

00:00

The Stateless Way to Encrypt a Session

The server and the client agree on actually two secrets. They are different secrets. The main resumption main secret is not used at all. So only the client actually stores the knowledge of this thing. Right? You can, you can also technically connect to another server and it'll be fine. How? Let's do this now. A new session is established. I want to resume a session. What do we do? We don't provide client certificate. We don't do any certificates or anything. It's literally just a data structure. And then encrypt that data structure with another key. That key must be known to the server and rotate it. But there is a key inside, inside

Transcript
Play full episode

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner