Hacker News new | ask | show | jobs
by mpyne 243 days ago
Perhaps more importantly to a non-U.S. nations is that there are a lot of military networks that touch the public Internet whose security from outside attack is more or less premised on F5's implementation of mutual TLS to CACs.

Finding a way to subvert that authentication or, better yet, bypass it entirely, could put U.S. military networks that can be reached over the public Internet at risk of remote exploitation. Those networks can often also reach other military networks not directly exposed to the public Internet.

1 comments

The same F5 responsible for the existence of the padding extension in TLS? And that still has predictable TCP sequence numbers by default.