Episode 378: Joshua Davies on Attacking and Securing PKI

Topics covered
Popular Clips
Episode Highlights
SSL to TLS
The transition from SSL to TLS marked a significant evolution in web security protocols. explains that SSL, developed by Netscape in the mid-1990s, was designed to provide security in a hostile network environment. However, concerns about a private company managing such a critical protocol led to its handover to the Internet Engineering Task Force (IETF), which renamed it to TLS. Despite the name change, the term SSL remains prevalent in the industry. notes, "The most popular library for TLS is called OpenSSL, and I don't think the term SSL is ever going to go away, even though nobody uses SSL anymore." 1 2.
TLS 1.3
TLS 1.3 introduced key improvements, notably reducing the number of messages needed to establish a secure connection. highlights that the handshake process was streamlined from seven messages to three, enhancing efficiency. This change allows the client to initiate the key exchange, assuming the server supports its preferred method, which is often the case. explains, "They also introduced the concept of what they call zero RTT handshake, where the client can assume that the server can do a handshake." This advancement is particularly beneficial for large-scale web services, where reducing latency is crucial 3 2.
Related Episodes


Episode 526: Brian Campbell on Proof of Possession Defenses
Answers 383 questions

Episode 514: Vandana Verma on the Owasp Top 10
Answers 383 questions

Episode 541: Jordan Harband and Donald Fisher on Securing the Supply Chain
Answers 383 questions

Episode 438: Andy Powell on Lessons Learned from a Major Cyber Attack
Answers 383 questions

Episode 395: Katharine Jarmul on Security and Privacy in Machine Learning
Answers 383 questions

Episode 535: Dan Lorenc on Supply Chain Attacks
Answers 383 questions

SE-Radio Episode 321: Péter Budai on End to End Encryption
Answers 383 questions

SE-Radio Episode 330: Natalie Silvanovich on Attack Surface Reduction
Answers 383 questions

Episode 385: Evan Gilman and Doug Barth on Zero-Trust Networks
Answers 383 questions

SE-Radio Episode 288: DevSecOps
Answers 383 questions

Episode 128: Web App Security with Bruce Sams
Answers 383 questions

Episode 66: Gary McGraw on Security
Answers 383 questions

SE-Radio Episode 314: Scott Piper on Cloud Security
Answers 383 questions

SE Radio 635: Stevie Caldwell on Zero-Trust Architecture
Answers 383 questions














