Hacker News new | ask | show | jobs
by stouset 2247 days ago
I'll just say I work at a large SF unicorn where we do this. We're not at 100% (getting anything to 100% when you're big enough is impossible), but the vast majority of everything is behind TLS 1.2 with unique certificates per server/app pair.

We're hoping to use SPIFFE/SPIRE to bring adoption even higher.

1 comments

I'm very impressed. I have only seen this in one place. It was a very old school brokerage and even they were running that over IPSEC network