The Cloudflare MTLS Vulnerability - A Deep Dive Analysis
Offered By: Hussein Nasser via YouTube
Course Description
Overview
Dive deep into a comprehensive analysis of the Cloudflare mTLS vulnerability in this 42-minute video. Explore the intricacies of the security flaw that persisted in Cloudflare's system for nearly two years, focusing on mutual TLS and client certificate revocation. Learn about certificate authentication, serial numbers, session resumption, and the specifics of the bug. Understand the timeline of events, the impact on certain endpoints, and the measures taken to address the problem. Gain valuable insights into cybersecurity practices and the complexities of managing large-scale systems through this detailed examination of a real-world vulnerability.
Syllabus
Intro
The Vulnerability
What happened?
Certificate Revocation
Rejecting certain endpoints
Certificate Authentication
Certificate serial number
Session Resumption PSK
The bug
How they addressed the problem
Taught by
Hussein Nasser
Related Courses
Introduction to Service Mesh with LinkerdLinux Foundation via edX Creating Multi Task Models With Keras
Coursera Project Network via Coursera Getting Started with Linkerd Service Mesh
Pluralsight (Almost) Secure by Default - Next Steps for Hardening Istio in Production Environments
CNCF [Cloud Native Computing Foundation] via YouTube Avoiding Catastrophe - Active Dendrites Enable Multi-Task Learning in Dynamic Environments
Yannic Kilcher via YouTube