Ask HN: TLS 1.3 and Post-Quantum Encryption for HN?
(ycombinator.com)
Could HN benefit from a TLS upgrade, as it's currently at TLS v1.2, (not e.g.: v1.3) (for me, at least)? Also could it benefit from being a leader in implementing post-quantum cryptography?
Could HN benefit from a TLS upgrade, as it's currently at TLS v1.2, (not e.g.: v1.3) (for me, at least)? Also could it benefit from being a leader in implementing post-quantum cryptography?
Using Kernel TLS (kTLS) (2023)
(delthas.fr)
Traditionally, the data path for sending HTTPS traffic is:
Traditionally, the data path for sending HTTPS traffic is:
We have an unusual concern when we use Let's Encrypt
(utoronto.ca)
One of the bits of recent TLS news is that Let's Encrypt is going to start offering 6-day TLS certificates.
One of the bits of recent TLS news is that Let's Encrypt is going to start offering 6-day TLS certificates.
TLS certificates were almost never particularly well verified
(utoronto.ca)
Recently there was a little commotion in the TLS world, as discussed in We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI.
Recently there was a little commotion in the TLS world, as discussed in We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI.
How to inspect TLS encrypted traffic
(apnic.net)
Do you want to analyse decrypted TLS traffic in Wireshark or let an Intrusion Detection System (IDS), like Suricata, Snort or Zeek, inspect the application layer data of potentially malicious TLS encrypted traffic?
Do you want to analyse decrypted TLS traffic in Wireshark or let an Intrusion Detection System (IDS), like Suricata, Snort or Zeek, inspect the application layer data of potentially malicious TLS encrypted traffic?
Rustls Outperforms OpenSSL and BoringSSL
(memorysafety.org)
ISRG has been investing heavily in the Rustls TLS library over the past few years. Our goal is to create a library that is both memory safe and a leader in performance.
ISRG has been investing heavily in the Rustls TLS library over the past few years. Our goal is to create a library that is both memory safe and a leader in performance.
Just want simple TLS for your .internal network?
(github.com/nh2)
Safely shareable TLS root CA for .internal networks using Name Constraints
Safely shareable TLS root CA for .internal networks using Name Constraints
WebPKI – Introduce Schedule of Reducing Validity (Of TLS Server Certificates)
(github.com/cabforum)
Subscriber Certificates issued on or after 1 September 2020 SHOULD NOT have a Validity Period greater than 397 days and MUST NOT have a Validity Period greater than 398 days.
Subscriber Certificates issued on or after 1 September 2020 SHOULD NOT have a Validity Period greater than 397 days and MUST NOT have a Validity Period greater than 398 days.
Google calls for halting use of WHOIS for TLS domain verifications
(arstechnica.com)
Certificate authorities and browser makers are planning to end the use of WHOIS data verifying domain ownership following a report that demonstrated how threat actors could abuse the process to obtain fraudulently issued TLS certificates.
Certificate authorities and browser makers are planning to end the use of WHOIS data verifying domain ownership following a report that demonstrated how threat actors could abuse the process to obtain fraudulently issued TLS certificates.
Show HN: Pyrtls, rustls-based modern TLS for Python
(github.com/djc)
pyrtls provides bindings to rustls, a modern Rust-based TLS implementation with an API that is intended to be easy to use to replace the ssl module (but not entirely compatible with it).
pyrtls provides bindings to rustls, a modern Rust-based TLS implementation with an API that is intended to be easy to use to replace the ssl module (but not entirely compatible with it).