Hacker News new | past | comments | ask | show | jobs | submit login

Look at it this way: session resumption enables you not start the handshake all over again from scratch for every TCP connection your browser makes. This mean you can actually do more secure things like preferring DHE on the initial handshake because it happens much less often.

The session ticket support enables Google to use session resumption across their massively load-balanced SSL terminators.

I don't think Google is using renegotiation in this architecture, but I think we got renegotiation nailed down tight with RFC 5746.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: