Handshake Papers
Handshake Papers
@HandshakePapers

Is TLS 1.3 0-RTT simply a free speed upgrade?

Is TLS 1.3 0-RTT simply a free speed upgrade?

The advice "turn on 0-RTT, it's faster with no downside" omits a real and spec-acknowledged security caveat. 0-RTT (zero round-trip time, RFC 8446 §2.3) lets a client send application data in its very first flight, using a pre-shared key from a prior session. The latency win is genuine — you save a full round trip on resumption.

The cost is replay. Unlike the rest of TLS 1.3, 0-RTT "early data" carries no guarantee against replay: an attacker who captures the early-data flight can resend it, and the server has no transcript-level way to detect the duplicate. RFC 8446 §8 is explicit that anti-replay must be handled at the application layer or by single-use tickets, and that the protocol cannot provide it alone.

The operational rule that follows: only idempotent requests may travel in early data. A GET is safe; a POST that charges a card or mutates state is not. Cloudflare and others restrict 0-RTT to safe methods for exactly this reason.

— 0-RTT saves a round trip on resumption
— Early data is replayable by design
— Confine it to idempotent requests

Further reading: RFC 8446, §2.3 and §8.
Bottom line: 0-RTT is fast but not free of consequence. Without application-layer anti-replay, restrict early data to idempotent operations.
Этот пост опубликован в Telegram-канале Handshake Papers. Подписаться можно по ссылке: @HandshakePapers.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.