On the Interplay between TLS Certificates and QUIC Performance
arXiv:2211.02421 · doi:10.1145/3555050.3569123
Abstract
In this paper, we revisit the performance of the QUIC connection setup and relate the design choices for fast and secure connections to common Web deployments. We analyze over 1M Web domains with 272k QUIC-enabled services and find two worrying results. First, current practices of creating, providing, and fetching Web certificates undermine reduced round trip times during the connection setup since sizes of 35% of server certificates exceed the amplification limit. Second, non-standard server implementations lead to larger amplification factors than QUIC permits, which increase even further in IP spoofing scenarios. We present guidance for all involved stakeholders to improve the situation.
camera-ready
References in corpus (2)
Cited by in corpus (7)
- QUIC is not Quick Enough over Fast Internet
- The Age of DDoScovery: An Empirical Comparison of Industry and Academic DDoS Assessments
- QUIC Hunter: Finding QUIC Deployments and Identifying Server Libraries Across the Internet
- Unconsidered Installations: Discovering IoT Deployments in the IPv6 Internet
- ReACKed QUICer: Measuring the Performance of Instant Acknowledgments in QUIC Handshakes
- Secure Middlebox-Assisted QUIC
- Waiting for QUIC: Passive Measurements to Understand QUIC Deployments