Earlier quoted context omitted.
Same thought here. And what if that connection breaks? Another single point of failure?
Multiple connections between CloudFlare and the Keyless SSL Server running at the customer site. Connections are reused, pipelined, load balanced etc.
Announcing Keyless SSL
11–20 of 190 posts
Re: Announcing Keyless SSL
#12Re: Announcing Keyless SSL
#13So the communication between Cloudflare and the actual SSL key holder is secured by… what? Another key? In that case, any compromise of Cloudflare’s key is the same as a compromise of the original SSL key (at least in the short term).
Re: Announcing Keyless SSL
#14Re: Announcing Keyless SSL
#15isn't this completely missing the point, i.e. banks being able to say 'no third parties can see our clients identifying information/balances/etc?' yes, the SSL key doesn't leave the bank, but everything it is protecting is..
Re: Announcing Keyless SSL
#16So CloudFlare won't get your private key, but will still get to see unencrypted plaintext for all traffic? Sounds like a huge improvement...
Re: Announcing Keyless SSL
#17After reading the beginning of the piece, I was expected something more...profound. Some deep mathematical breakthrough or something. Instead they separate the actual key signing, delegating it to the customer's device. That's nice and useful, but isn't quite what I was expecting.
Re: Announcing Keyless SSL
#18Re: Announcing Keyless SSL
#19isn't this completely missing the point, i.e. banks being able to say 'no third parties can see our clients identifying information/balances/etc?' yes, the SSL key doesn't leave the bank, but everything it is protecting is..