That's from reading old papers, I don't know if anything changed now.
Could you elaborate on the technical details on user authentication? (If that's not top-super-secret) I guess it's just like accounts.google.com for Enterprise with mandatory 2FA (username+password+U2F key?). Does it work the same on mobile/Android (U2F via NFC or codes)?
https://itunes.apple.com/us/app/google-smart-lock/id11520663...
There's tpm and secure boot - does the (presumably signed, in the trusted boot->os->user binary/service-path) agent access signing services from tpm - backed by a key in tpm, and use that to identify itself as an authentic agent?
Otherwise I can't see how an (admin) user couldn't extract the key from ram and run the os and agent in a vm?
Um, what? Did client certs get removed from HTTP 2?
Servers can ask the client to fall back to HTTP 1.1 instead, and then use client-certificates there.
14 months ago: "No. But TLS!" https://news.ycombinator.com/item?id=11556762
7 months ago: "421" https://news.ycombinator.com/item?id=13022596
Maybe it would be worth the time to test out the various implementations if someone has not already done so?
--
Doing some preliminary research, support is still a working draft https://datatracker.ietf.org/doc/draft-bishop-httpbis-http2-... source: https://daniel.haxx.se/blog/2016/08/18/http2-connection-coal...