mTLS: When certificate authentication is done wrong
In this post, we'll deep dive into some interesting attacks on mTLS authentication. We'll have a look at implementation vulnerabilities and how developers can make their mTLS systems vulnerable to user impersonation, privilege escalation, and information leakages.
Discussion around the web
- Hacker News84 · 20 💬
Score breakdown
- Technical depth85
- Practical value60
- Originality85
- Writing quality82
- Source reputation85
- Recency0
- External engagement27
- On-site engagement0
More like this
Engineering at Meta60
How Meta built large-scale cryptographic monitoring
unknown·13 min read
The Cloudflare Blog52
Keyless SSL: The Nitty Gritty Technical Details
unknown·26 min read
The Cloudflare Blog63
Keeping the Internet fast and secure- introducing Merkle Tree Certificates
unknown·23 min read
The GitHub Blog63
Gaining kernel code execution on an MTE-enabled Pixel 8
Man Yue Mo·unknown·34 min read
Engradar shows a summary and links to the original article. The full article is hosted on github.blog.