Home / Companies / Speedscale / Blog / Post Details
Content Deep Dive

Under the Hood with Go TLS and eBPF

Blog post from Speedscale

Post Details
Company
Date Published
Author
Shaun Duncan
Word Count
3,939
Company Posts That Month
13
Language
English
Hacker News Points
-
Post removed?
No
Summary

eBPF can capture plaintext TLS traffic by attaching user-space probes before encryption and after decryption, a relatively simple process for OpenSSL applications using stable SSL_read and SSL_write symbols, but substantially more complex for Go programs. Go uses statically linked crypto/tls code, places TLS function symbols at binary-specific addresses, may strip needed symbol tables during compilation, and uses ABI conventions and dynamically resizing stacks that make standard uretprobes unreliable. The proposed approach targets unstripped Go binaries built with newer ABIInternal-compatible Go versions, locates crypto/tls.(*Conn).Read and Write symbols, disassembles their machine code to identify RET instructions, and attaches entry probes plus custom offset-based probes at each return instruction. Entry probes retain pointers to byte-slice arguments in eBPF maps, while return probes obtain the number of processed bytes from architecture-specific registers, read the plaintext data, split it into fixed-size chunks, and transmit it to user space through perf event arrays for further handling. Although the method requires per-binary inspection, ABI awareness, architecture-specific disassembly, and careful eBPF memory handling, it provides deep TLS visibility without relying on certificate interception or proxy-based monitoring.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.