Subtleloop

Subtleloop

Independent coverage of infrastructure, networking and data practice.

Security

Understanding TLS 1.3 Session Resumption

August 29, 2026

TLS 1.3 collapsed the handshake to a single round trip, but the real latency win for repeat visitors comes from resumption. A client presenting a valid pre-shared key can skip straight to encrypted application data, which on mobile networks can be the difference between a page that feels instant and one that feels broken.

The trade-off lives in forward secrecy. Tickets encrypted with a long-lived server key mean captured traffic can be decrypted later if that key leaks. Operators who care rotate ticket keys on a strict cadence - daily is common, hourly is not crazy - and accept the small CPU cost of more full handshakes.

Continue reading →

Engineering

A Field Guide to Graceful Degradation

July 25, 2026

Architectures need an explicit hierarchy of failure. Recommendation engines should yield before purchasing flows break; query auto-complete should disable before search fails; generated previews should drop before source content vanishes. Formulating this priority map and reinforcing it through isol…

Security

Managing Secrets Without Losing Sleep

May 8, 2026

Organizations typically transition between two distinct security phases: managing static secrets in encrypted archives and preparing for formal compliance audits. Navigating that gulf requires automated key cycling, immutable audit records, and acknowledging that human operators must not access live…

Operations

Multi-Region Failover Planning

September 2, 2026

Geographic disaster recovery success is determined long before an outage strikes. Establishing acceptable replication lag and designating operational authority to execute failover appear to be policy questions, but they dictate core technical parameters ranging from database clustering to telemetry …

Engineering

When to Choose a Queue Over a Request

June 14, 2026

Traditional RPC calls remain popular due to straightforward causality: the client makes an invocation, waits for the response, and monitors latency directly. Asynchronous message queuing becomes essential when background tasks outlast active connections or when sudden volume surges threaten to overw…

More reading

About us

We cover the unglamorous middle of software: queues that back up, caches that lie, and DNS at 3 a.m. Everything is written from real operational experience.

More about the project →