Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>> doesn't usually authenticate its traffic

> Yes it does. ntp uses TLS to communicate with it's well known locations.

My knee-jerk reaction is that TLS is not authentication. After skimming through the relevant spec [0], it is interesting how NTP uses TLS.

[NTS-KE] uses TLS to establish keys, to provide the client with an initial supply of cookies, and to negotiate some additional protocol options. After this, the TLS channel is closed with no per-client state remaining on the server side. [0]

0. https://datatracker.ietf.org/doc/html/rfc8915



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: