Website Security & Threat Management
Change the (S)Channel! Deconstructing the Microsoft TLS Session Resumption bug

Change the (S)Channel! Deconstructing the Microsoft TLS Session Resumption bug

2/11/2016 · Patrick R. Donahue

What this post added

This post details Cloudflare's investigation and deconstruction of a bug within Microsoft's SChannel TLS implementation. The bug caused connection failures or security downgrades (TLS 1.2 to TLS 1.0) when clients using SChannel encountered TLS session tickets being renewed during an abbreviated handshake. Cloudflare's proactive approach to TLS session ticket management, including frequent key regeneration for security and scalability, exposed this underlying issue in Microsoft's implementation. The post highlights Cloudflare's role in identifying, troubleshooting, and ultimately contributing to the resolution of this critical security vulnerability affecting a wide range of Microsoft products.

Read the original post ↗