We need to talk about Session Tickets

1 · Filippo Valsorda · Sept. 28, 2017, 4:24 p.m.
More specifically, TLS 1.2 Session Tickets. Session Tickets, specified in RFC 5077, are a technique to resume TLS sessions by storing key material encrypted on the clients. In TLS 1.2 they speed up the handshake from two to one round-trips. Unfortunately, a combination of deployment realities and three...