Hacker News new | ask | show | jobs
by solenoid0937 24 days ago
You don't understand the use case or audience of this article:

> If your infra consistently enforces mTLS

This is for mutual authentication in corporate infrastructure. Attestation is a critical security property for these environments.

1 comments

> Attestation is a critical security property for these environments.

No it's not. Every corporate network to which I've connected worked just fine without it.

> Every corporate network to which I've connected worked just fine without it.

Just because it appears to be working fine doesn't mean you are in control of it. Without hardware attestation, how do you know the machines are running the software you think they are?

My spouse's local Linux account on my laptop works fine with their password set as their username as well. Is it technically secure, though?