YoVDO

The Cloudflare MTLS Vulnerability - A Deep Dive Analysis

Offered By: Hussein Nasser via YouTube

Tags

Cybersecurity Courses Network Security Courses Multi-task Learning (MTL) Courses

Course Description

Overview

Dive deep into a comprehensive analysis of the Cloudflare mTLS vulnerability in this 42-minute video. Explore the intricacies of the security flaw that persisted in Cloudflare's system for nearly two years, focusing on mutual TLS and client certificate revocation. Learn about certificate authentication, serial numbers, session resumption, and the specifics of the bug. Understand the timeline of events, the impact on certain endpoints, and the measures taken to address the problem. Gain valuable insights into cybersecurity practices and the complexities of managing large-scale systems through this detailed examination of a real-world vulnerability.

Syllabus

Intro
The Vulnerability
What happened?
Certificate Revocation
Rejecting certain endpoints
Certificate Authentication
Certificate serial number
Session Resumption PSK
The bug
How they addressed the problem


Taught by

Hussein Nasser

Related Courses

Computer Security
Stanford University via Coursera
Cryptography II
Stanford University via Coursera
Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Building an Information Risk Management Toolkit
University of Washington via Coursera
Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network