TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

TLS Mastery

152 pointsby rodrigo975about 4 years ago

10 comments

friend-monoidabout 4 years ago
I bought it and skimmed through most of it, and I have a hard time recommending it personally. It’s really short on the crypto and offers no insight into why TLS behaves the way it does. I would like to at least see an explanation of the TLS handshake process, but there is none. It’s a lot of “using openssl s_client”-type of discussion; i.e. how to use it, not so much on how it works, and that applies to most of the book (including the ocsp parts).<p>Practical, not necessarily theoretical; but if that’s what you are looking for, then it’s a great book.
评论 #26771207 未加载
eandreabout 4 years ago
TLS always felt like a scary beast to me until I started writing Go. The crypto&#x2F;tls package is amazing and makes doing incredible things with TLS super easy. We&#x27;re using it in lots of interesting ways behind the scenes for Encore, leveraging Vault, a custom CA, SPIFFE for workload identity and more.<p>I haven&#x27;t read the book, but learning more about TLS is easily one of the best time investments I&#x27;ve made.
评论 #26770983 未加载
评论 #26776325 未加载
srathiabout 4 years ago
I recommend this blog post as a good primer for TLS.<p><a href="http:&#x2F;&#x2F;www.moserware.com&#x2F;2009&#x2F;06&#x2F;first-few-milliseconds-of-https.html" rel="nofollow">http:&#x2F;&#x2F;www.moserware.com&#x2F;2009&#x2F;06&#x2F;first-few-milliseconds-of-h...</a>
评论 #26777011 未加载
Volineabout 4 years ago
In my opinion, Michael W Lucas is one of the best tech writers working today. I have made great use of his books Absolute OpenBSD, SSH Mastery, and Httpd &amp; Relayd Mastery.<p>He also wrote Absolute FreeBSD and PGP &amp; GPG: Email for the Practical Paranoid, among many others.
smitty1eabout 4 years ago
Feisty Duck has some great material and training in this vein =&gt; <a href="https:&#x2F;&#x2F;www.feistyduck.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.feistyduck.com&#x2F;</a><p>I just sat through the 4 1&#x2F;2 day online training they offer, and thought it was worth the price, as long as the company was picking up the tab.
calpatersonabout 4 years ago
Can someone who has read it post their review?<p>The contents look good and I feel like it might help me patch some holes in my knowledge. It has the advantage of at least looking like it&#x27;s up to date (a lot of SSL writing has been obsoleted).
评论 #26770583 未加载
评论 #26770506 未加载
Tepixabout 4 years ago
My first impression is that a book called &quot;TLS Mastery&quot; should dive deeper than what the toc suggests this one does.<p>TLS privacy seems to be a big rather little-known topic. OCSP leaks etc. Does this book cover it in-depth?
ancardaabout 4 years ago
Anyone know if the book covers ESNI? Or if there&#x27;s a good resource on how to set that up with Nginx, CloudFlare DNS, and Let&#x27;s Encrypt?<p>EDIT: Okay, it looks like this is not yet ready for most people to use.
评论 #26772570 未加载
评论 #26773261 未加载
baybal2about 4 years ago
I learned few years ago that you can do TLS auth without client side certs.<p>People were always surprised how they stay logged in after clearing cookies.
评论 #26770590 未加载
评论 #26795252 未加载
评论 #26770348 未加载
评论 #26770270 未加载
superkuhabout 4 years ago
Step 1. Give up volition to a third party certificate authority and hope your internet service is never controversial enough to get it revoked like sci-hub.
评论 #26771936 未加载
评论 #26778021 未加载