[TLS] Another [Well-deserved] attack on TLS CCA

Anders Rundgren <anders.rundgren@telia.com> Tue, 18 June 2013 18:31 UTC

Date: Tue, 18 Jun 2013 20:30:58 +0200
Subject: [TLS] Another [Well-deserved] attack on TLS CCA
Luckily for all users Google didn't select TLS CCA (Client Certificate
Authentication) for their coming U2F system; only a moron would base a
future consumer authentication system on a scheme that is only suited
for VPN tunnels and invisible authentications like as ChannelID.

What's missing you may wonder?  Well, how about

- Compatibility with web sessions including timeout and logout
- A working credential filtering system
