Handshake Papers
29 subscribers
79 photos
16 videos
1 file
251 links
Long-form deep dives into TLS, certificates, and HTTPS internals. We read the RFCs and CA studies so you understand what actually happens in that handshake.
Download Telegram
Forwarded from AFF.TOP - про арбитраж трафика и CPA рынок!
This media is not supported in your browser
VIEW IN TELEGRAM
Google расширил Data Manager

Google интегрировал инструмент Data Manager в GA и DV360 для удобной передачи first-party данных, что дает рост ROAS до 26%. Для арбитража трафика прямого применения у офлайн-данных нет, однако инструмент можно использовать для манипуляции алгоритмами: отправка синтетических конверсий через API поможет скорректировать оптимизацию и направить автостратегии на поиск нужной аудитории.

➡️ Читайте на сайте: https://aff.top/blog/google-rasshiril-data-manager

🧠 Ещё больше инсайтов → в канале AFF.top
Forwarded from AffPapa! Клуб спящих бизнесменов! Потрачено!
Через 30 минут открытие канала CMO Трафик Кардинала Макса Огненого https://t.me/+BWTUr7fxVqoyMWE0

Он обещает нещадно ебать, а мы будем смотреть!
Can you drop the HTTP-to-HTTPS redirect once HSTS is set?

The optimization "HSTS handles the upgrade, so I can remove my 301 redirect" contains a fatal first-visit gap. HSTS (HTTP Strict Transport Security, RFC 6797) is a Trust On First Use mechanism. The browser only learns your HSTS policy by receiving the Strict-Transport-Security header — and it can only receive that header over a successful HTTPS response. A browser that has never visited you, or whose cached policy expired, has no instruction yet.

So the very first request a new client makes to http://yoursite must still be answered. If you removed the redirect, that plaintext request either fails or is served over HTTP, exactly the window an on-path attacker uses for SSL-stripping. The redirect is what gets that first connection onto HTTPS so the HSTS header can ever be delivered.

The only way to close the first-visit gap entirely is the preload list (compiled into the browser), and even that requires you to keep serving HTTPS correctly. The redirect stays either way.

— HSTS is Trust On First Use over HTTPS
— First plaintext request still needs answering
— Removing the redirect reopens SSL-stripping

Further reading: RFC 6797, §8.3 and §14.6.
Bottom line: Keep the HTTP-to-HTTPS redirect. HSTS protects return visits; the redirect protects the first one.
Why can an HSTS header with the wrong directive be worse than no header at all?

HSTS (RFC 6797) is usually framed as pure upside: force HTTPS, prevent downgrades. But the header is a binding, browser-enforced commitment with a state that outlives the response, and two directives turn it into a foot-gun: includeSubDomains and a long max-age.

Consider the failure mode. You set Strict-Transport-Security: max-age=63072000; includeSubDomains on example.com. Every browser that has seen this header will now refuse plain HTTP — and refuse to bypass certificate errors — for two years, across every subdomain, including ones you do not control today and any you create tomorrow. If a subdomain later needs to serve HTTP (a legacy device, a third-party tool, an acquired property with a broken certificate), it is unreachable for returning visitors. There is no server-side undo for browsers that already cached the policy; you can only serve max-age=0 and hope each affected client revisits the apex over HTTPS to clear it.

The sharper trap is asymmetric reach. The policy is keyed to the host that sent it, but includeSubDomains projects it downward onto hosts that never sent any header and may not be ready. The commitment is made by the parent, paid by the children.

Evidence vs. speculation: the clearing mechanism (max-age=0 on a successful HTTPS response) is normative in RFC 6797 §6.1.1; the operational pain of subdomain lockout is a recurring, documented incident pattern.

Further reading: RFC 6797 §6.1, §8.1, §11.

Bottom line: HSTS state is sticky and client-side — add includeSubDomains only after auditing every present and future subdomain's TLS readiness, because the only rollback is max-age=0 plus a hope that each browser revisits to clear the cached commitment.
Forwarded from AFF.TOP - про арбитраж трафика и CPA рынок!
This media is not supported in your browser
VIEW IN TELEGRAM
Xchat удалён из App Store и Google play

Google Play и App Store удалили мессенджер XChat, продвигавшийся Илоном Маском как сервис с шифрованием без рекламы. Несмотря на трафик из X.com, приложение исключили из сторов. Причиной мог стать отказ от трекинга, что мешает монетизации и антифрод-системам площадок. Кейс доказывает: отсутствие рекламных инструментов делает софт уязвимым, а медийная поддержка не спасает продукт, если его политика нарушает правила маркетплейсов.

➡️ Читайте на сайте: https://aff.top/blog/xchat-udalen-iz-app-store-i-google-play

🧠 Ещё больше инсайтов → в канале AFF.top
Forwarded from AFF.TOP - про арбитраж трафика и CPA рынок!
This media is not supported in your browser
VIEW IN TELEGRAM
В Facebook Ads Manager появилась метрика Creative Diversity

Meta представила метрику Creative Diversity для оценки разнообразия креативов. Алгоритм Generative Recommender анализирует стиль, тему, тип хука и формат объявлений. Простое изменение цвета или ракурса теперь не работает: система пессимизирует похожие подходы. Для эффективного залива арбитражникам придется тестировать принципиально разный контент, чтобы алгоритмы лучше находили аудиторию. Инструмент выйдет из беты до конца года.

➡️ Читайте на сайте: https://aff.top/blog/v-facebook-ads-manager-poiavilas-metrika-creative-diversity

🧠 Ещё больше инсайтов → в канале AFF.top
Forwarded from AFF.TOP - про арбитраж трафика и CPA рынок!
This media is not supported in your browser
VIEW IN TELEGRAM
Твои переписки с ChatGPT читают люди

OpenAI привлекает подрядчиков для ручного анализа диалогов с ChatGPT, чтобы повысить качество модели. В ходе проверки конфиденциальная информация пользователей попадает к третьим лицам. Для сферы CPA это несет прямые риски: уникальные связки, креативы и структуры лендингов, созданные нейросетью, перестают быть приватными. Главный вывод — любая информация, переданная ИИ, может быть изучена извне, что ведет к быстрому выгоранию профитных подходов …

➡️ Читайте на сайте: https://aff.top/blog/tvoi-perepiski-s-chatgpt-chitaiut-liudi

🧠 Ещё больше инсайтов → в канале AFF.top
Does your browser actually reject a revoked certificate?

The assumption "if a certificate is revoked, my browser will block it" describes how revocation is supposed to work, not how it does. Two legacy mechanisms — CRLs (Certificate Revocation Lists, RFC 5280) and OCSP (Online Certificate Status Protocol, RFC 6960) — both fail open. CRLs grew too large to download routinely. OCSP checks add latency and leak browsing to the CA, so browsers adopted soft-fail: if the responder is slow or unreachable, the browser proceeds as if the certificate were valid.

Adam Langley's well-known critique called soft-fail revocation "useless," because any attacker capable of using a stolen certificate can also block the revocation check — the same network position enables both. Chrome largely disabled live OCSP years ago in favor of CRLSets, a curated push of high-priority revocations; Firefox built CRLite, a compressed Bloom-filter structure pushed to the browser.

These push-based systems work because the browser already has the answer before the handshake, so there is nothing for an attacker to block. But they cover a subset of revocations, not all.

— CRL/OCSP fail open by default
— Soft-fail is defeatable by the same attacker
— CRLSets/CRLite push a curated subset

Further reading: Langley, "Revocation checking and Chrome's CRL" (2012); Firefox CRLite.
Bottom line: Live revocation checking is mostly theater. Browser-pushed lists and short certificate lifetimes are what actually protect you.
What actually lets Firefox check revocation for the entire Web Public Key Infrastructure in a few megabytes?

The answer is CRLite, and the mechanism is a worked example of probabilistic data structures meeting a real security need.

Revocation at web scale is a data problem. Certificate Revocation Lists (CRLs, RFC 5280) are large and stale; OCSP (RFC 6960) is per-query and privacy-leaking. CRLite, from a 2017 IEEE S&P paper by Larisch et al. and now shipping in Firefox, asks: can we push the full revocation state of every publicly-trusted certificate to the client?

The enabling insight is Certificate Transparency. Because CT logs (RFC 6962) enumerate essentially all issued certificates, the universe of certificates is knowable. CRLite encodes the revoked subset against that known universe using a cascade of Bloom filters. A single Bloom filter has false positives; a cascade layers additional filters trained only on the items the previous layer got wrong, driving the aggregate false-positive rate to zero over the known set.

The result compresses hundreds of millions of certificates' revocation status into roughly 1–10 MB, with daily delta updates. Lookups are local, instant, and leak nothing to the CA.

The constraint: it only works for certificates the client's filter knows about, so it depends on comprehensive CT coverage and timely updates.

Further reading: Larisch et al., "CRLite" (IEEE S&P 2017); RFC 6962; Mozilla's CRLite rollout posts.

Bottom line: CRLite turns revocation into a local lookup by exploiting CT's complete certificate census plus a zero-false-positive Bloom filter cascade.
Forwarded from AFF.TOP - про арбитраж трафика и CPA рынок!
This media is not supported in your browser
VIEW IN TELEGRAM
Google тестирует оплату за контент сайта

Google запустил тест программы AI Contribution Pilot, предлагая вебмастерам выплаты через Search Console за контент, повлиявший на ответы ИИ в Gemini и AI Overviews. Алгоритмы оценки вклада и формулы расчетов непрозрачны, а суммы пока скромные. Главный итог: создан важный прецедент прямой компенсации за использование авторских материалов в генеративной выдаче.

➡️ Читайте на сайте: https://aff.top/blog/google-testiruet-oplatu-za-kontent-saita

🧠 Ещё больше инсайтов → в канале AFF.top
Forwarded from AffPapa! Клуб спящих бизнесменов! Потрачено!
Можно идеально настроить фарм и всё равно улететь нахуй, потому что IP до тебя уже убили)

У проксей вообще классно устроено: каждый второй пишет про чистейшие IP, а что тебе реально выдали, узнаёшь когда уже начались проблемы

Самое веселое, что обычно качество прокси узнаешь только тогда, когда начинаются проблемы. На сайте тебе написали «чистые IP», а что реально попалось, сюрприз.

В Relayox не сваливают все адреса в один пул. Степень фильтрации выбираешь сам. Нужен большой выбор IP, берёшь шире. Работаешь с капризной площадкой, сужаешь отбор. А не вот это вот «у нас премиум, мамой клянусь»

Короче можете вообще не верить этому посту. Тест стоит $1. Берёте 200 МБ или isp, проверяете на своей задаче и сами решаете.
А промокод AFFPAPA даст скидку 30% 🤑
https://relayox.com/
Forwarded from AFF.TOP - про арбитраж трафика и CPA рынок!
This media is not supported in your browser
VIEW IN TELEGRAM
В публичный доступ вышли Gemini 3.8 Live и Gemini 3.8 Live Extended Thinking

Google представила Gemini 3.8 Live и Extended Thinking — голосовые ИИ-модели с поддержкой 97 языков и функцией параллельного мышления. Инструмент умеет выполнять фоновые задачи и анализировать видео в реальном времени, не прерывая диалог. Высокое качество распознавания речи и доступ через API позволяют эффективно использовать модели для автоматизации воронки продаж, обработки лидов и создания интерактивных креативов.

➡️ Читайте на сайте: https://aff.top/blog/v-publichnyi-dostup-vyshli-gemini-3-8-live-i-gemini-3-8-live-extended-thinking

🧠 Ещё больше инсайтов → в канале AFF.top
Евгений Юрьевич все таки навайбкодил свой «NeAntik», полностью сделанный нейронками антидетект. По прохождению тестов там конечно есть вопросы, но функционал не хуже индиго!) Пока есть только версия под macOS. @cparip

Подробнее: https://cpa.rip/services/neantik/

🤩 Adset.Pro — AI-трекер, PWA и игровые ленды в одном месте. −50% по промокоду CPARIP
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from AFF.TOP - про арбитраж трафика и CPA рынок!
This media is not supported in your browser
VIEW IN TELEGRAM
Топ 5 spy-сервисов для Facebook

В обзоре сравниваются пять spy-сервисов для Facebook: от бесплатной Library до профессиональных AdSpy и Tyver. Автор оценивает их по глубине аналитики, охвату и цене. Главный вывод: бесплатные решения не показывают профитность креативов, поэтому для работы в плюс необходим платный софт. Лидером рейтинга стал Tyver за баланс стоимости и функций. Инвестиции в спай окупаются за счет быстрого поиска рабочих подходов и экономии бюджета на тестах новы…

➡️ Читайте на сайте: https://aff.top/blog/top-5-spy-servisov-dlia-facebook

🧠 Ещё больше инсайтов → в канале AFF.top
Forwarded from AFF.TOP - про арбитраж трафика и CPA рынок!
This media is not supported in your browser
VIEW IN TELEGRAM
Meta добавила платную подписку на свои соцсети

Meta расширяет программу Meta Verified, внедряя подписку Meta One с тремя тарифами стоимостью до 19,99 долларов. Пакеты включают верификацию и доступ к ИИ компании. Несмотря на скепсис по поводу нейросетей, синяя галочка остается важным инструментом для арбитража. В нише УБТ верифицированные аккаунты моделей повышают траст и упрощают залив. Подписка становится техническим расходом, требующим оценки окупаемости в рамках связок.

➡️ Читайте на сайте: https://aff.top/blog/meta-dobavila-platnuiu-podpisku-na-svoi-socseti

🧠 Ещё больше инсайтов → в канале AFF.top
Forwarded from iGamingNews
Media is too big
VIEW IN TELEGRAM
🏠💶 iGaming-оператор Dragon Money запустил в Telegram-каналах посев поддельных новостей, имитирующих публикации The Athletic, MMA Fighting и пост инвестора Роберта Кийосаки в соцсети X, для продвижения собственного розыгрыша дома

🔍 Для каждой аудитории оператор реализовал отдельный сюжет с упоминанием бренда. В футбольном канале новость обыгрывает летнюю трансферную сагу, в которой нападающий ФК «Атлетико Мадрид» Хулиан Альварес зарабатывает на продукте оператора для выплаты отступных и перехода в ФК «Барселона». В крипто-канале новость сообщает о продаже Робертом Кийосаки всей своей криптовалюты ради депозита, который он называет лучшим способом вложиться в недвижимость. В канале об ММА сюжет строится на том, что глава UFC Дана Уайт запретил бойцам играть у оператора из-за идущего розыгрыша жилья


@igaming_news
Please open Telegram to view this post
VIEW IN TELEGRAM
Network roundup — across the board:

@ThePressHook — Real digital PR plays that landed coverage in major outlets: angle…
@FeedHeretic — Debunking LinkedIn 'guru' advice with what the feed actually rewards…
@BidStack101 — Header bidding explained without the AdTech jargon: what Prebid,…
@thechainleaks — The crypto-affiliate grapevine: which networks just changed payouts,…
What actually happens during a TLS 1.3 KeyUpdate, and why isn't it the same as renegotiation?

The distinction matters because TLS 1.3 deliberately killed renegotiation — a feature with a long abuse history — and replaced it with something narrower.

TLS 1.2 renegotiation let either party run a fresh handshake inside an existing connection, re-authenticating or rekeying mid-stream. It enabled the 2009 renegotiation attack (CVE-2009-3555), where injected plaintext was spliced ahead of a client's authenticated request. RFC 5746 patched it, but the complexity remained.

TLS 1.3 (RFC 8446 §4.6.3) removes renegotiation entirely. For rekeying it offers KeyUpdate: a post-handshake message saying "derive the next traffic key." The new application-traffic secret is computed by applying HKDF-Expand-Label with the label "traffic upd" to the current secret — a one-way ratchet forward. No new key exchange, no re-authentication, no transcript renegotiation. KeyUpdate can request the peer also update (update_requested), giving bidirectional rekey.

What it cannot do is change identities or parameters. That deliberate limitation is the security gain: there is no in-band way to re-handshake, so the renegotiation attack surface is structurally absent. Re-authentication, where needed, is handled separately via post-handshake authentication (CertificateRequest), not by rekeying.

KeyUpdate exists mainly to bound the data encrypted under a single key, respecting AEAD usage limits.

Further reading: RFC 8446 §4.6.3, §4.6.2; RFC 5746; CVE-2009-3555.

Bottom line: KeyUpdate ratchets traffic keys forward via HKDF without any new handshake — it rekeys but, unlike renegotiation, cannot re-authenticate or re-parameterize, which is precisely why it's safe.
Forwarded from AFF.TOP - про арбитраж трафика и CPA рынок!
This media is not supported in your browser
VIEW IN TELEGRAM
В Telegram Ads добавили Banner in Bot

В Telegram Ads появился формат Banner in Bot для показа рекламы внутри ботов с аудиторией от 1000 человек. Инструмент таргетируется не на площадки, а на пользователей — по интересам, номерам телефонов и подпискам. Пока доступны только текстовые креативы по ставкам Target Users. Новинка позволяет напрямую через стандартный кабинет охватывать целевую аудиторию прямо в их диалогах с ботами.

➡️ Читайте на сайте: https://aff.top/blog/v-telegram-ads-dobavili-banner-in-bot

🧠 Ещё больше инсайтов → в канале AFF.top
Forwarded from AffPapa! Клуб спящих бизнесменов! Потрачено!
📈 Приводи клиентов и поднимайся в Grand Prix 1 Million

GameChange Partners запускает трехмесячное соревнование для партнеров с общим призовым фондом до $1 000 000.


➡️ С сентября по ноябрь 2026 участники соревнуются в четырех дивизионах: Champions, Pro, Rising и Rookie.

⭐️ Твой результат определяет место в рейтинге, а результат всего дивизиона влияет на размер наград. При перевыполнении плана множитель призовых может вырасти до ×2.5.


⭐️GCP - это CPA и RS, 100+ GEO, прозрачная статистика и аналитика для работы и масштабирования трафика.


☄️ Подробнее о GCP ☄️

➡️ Чтобы попасть в Grand Prix, заполни анкету. В зачет пойдут новые клиенты, привлеченные после вступления.

☄️ Вступить в Grand Prix ☄️
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from AFF.TOP - про арбитраж трафика и CPA рынок!
This media is not supported in your browser
VIEW IN TELEGRAM
Anthropic готовит к запуску Claude Money

Anthropic анонсировала Claude Money — ИИ-сервис для управления личными финансами и автоматизации платежей. Инструмент позволяет подключать банковские карты для анализа расходов, планирования бюджета и проведения транзакций. Это переход от консультационных моделей к полноценным финансовым агентам. Внедрение технологии позволит пользователям делегировать нейросети рутинные задачи, включая оплату токенов и подписок на необходимые рабочие сервисы.

➡️ Читайте на сайте: https://aff.top/blog/anthropic-gotovit-k-zapusku-claude-money

🧠 Ещё больше инсайтов → в канале AFF.top