Skip to content

Archive

Transport Security

3 articles
Cybersecurity 19 Sep 2026 5 min read

TLS 1.3 Early Data Trades One Round Trip for Replay Exposure

A resumed TLS 1.3 connection can carry application bytes before the server finishes the new handshake. That latency reduction changes a security boundary: early data is protected in transit, yet the protocol does not give it the same replay property as ordinary post-handshake application data. The distinction matters when an endpoint maps one request to a state-changing operation. A captured early-data flight can be presented again under conditions in which a server accepts it, so confidentiality and integrity on the wire do not imply single execution.

Cybersecurity 14 Sep 2026 7 min read

Certificate Pinning Trades Broad Trust for Operational Coupling

A mobile application can reject a perfectly valid TLS certificate even when the hostname matches, the certificate is current, and its chain terminates at a trusted public root. That rejection can be intentional. A pinning policy adds another condition: some element of the authenticated certificate chain must match identity material that the application already expects. The extra check narrows trust, but it also changes failure ownership. Normal Web PKI validation delegates a large part of certificate trust to platform root stores and certification authorities. Pinning moves part of that decision into application configuration and release management. A certificate rotation that is routine for a browser can become an outage for a pinned client.

Cybersecurity 11 Sep 2026 9 min read

Keep TLS Certificate Verification Enabled

An HTTPS client does more than encrypt bytes. During the TLS handshake, it also checks evidence about the server’s identity. If application code disables those checks, the connection can remain encrypted while being connected to an unintended endpoint. That distinction is central to secure TLS use. Encryption protects data against passive observation, but authenticated encryption to the wrong peer does not establish the identity the application intended to contact. The practical rule is: keep certificate-chain and hostname verification enabled, and repair trust configuration instead of bypassing verification.