HN Hall of Fame Weekly email

The First Few Milliseconds of an HTTPS Connection (2009)

www.moserware.com Books & learning Tutorials & guides Web & internet Class of 2015-07 Hall of Fame
Screenshot of www.moserware.com captured 2026-07-20
Page preview · captured 2026-07-20

Resurfaced independently across 8 calendar years, with breakout response in 3 of them.

submissions
11
submitters
11
observed span
2009–2020
peak thread · 37 comments
549 pts
latest 20+ return · 2020-10-20
190 pts

Submission timeline

2007–2026

One slot for every year since HN launched. Height is that year's peak points; orange marks a 100+ point or 50+ comment breakout. Select a bar to open its strongest thread.

First comments on top threads

HN comment order

In addition to this, with SPDY around, these first milliseconds are becoming even more important. Since SPDY requires some sort of negotiation between server and client to agree they both support the protocol, this creates a problem for the first request: how do you know a server supports SPDY without having seen a response from said server? Note that the regular HTTP Accept negotiation is not enough since the browser should already pipeline multiple requests before having seen a response…

This is a fine article. Unfortunately, it describes very specifically how not to verify an PKCS RSA signature, perpetuating a mistake that screwed over browser vendors a couple years back: http://www.matasano.com/log/558/public-key-signature-forgery... To wit: you verify specifically cannot look at the SHA-1 hash at the end of an RSA block and compare it to your own hash, because there are hundreds of zillions of other RSA blocks that can result from the RSA algorithm that could contain a SHA-1 block of…

tptacek·236-point thread·

Please note that this is from 2009 and a lot of things have changed. If you read it consider it a history lesson of how TLS was in 2009, not how it is today.

hannob·190-point thread·

This makes a lot of sense right now, especially that the next major version of Chrome will mark HTTP websites as invalid

The first top-level comment from each of the four biggest threads, in HN’s own order. Excerpts are shortened; open a comment for full context.

Breakout years
3

100+ points or 50+ comments

Total points
1083

reference only — not used in Hall rules or ranking

Total comments
108

reference only — not used in Hall rules or ranking

Every submission