TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Industry Concerns about TLS 1.3

23 pointsby m0nasticover 8 years ago

4 comments

runesoerensenover 8 years ago
Good response <a href="https:&#x2F;&#x2F;www.ietf.org&#x2F;mail-archive&#x2F;web&#x2F;tls&#x2F;current&#x2F;msg21278.html" rel="nofollow">https:&#x2F;&#x2F;www.ietf.org&#x2F;mail-archive&#x2F;web&#x2F;tls&#x2F;current&#x2F;msg21278.h...</a>
评论 #12561234 未加载
wolf550eover 8 years ago
So banks want to continue not supporting PFS. Banks can afford to log the private ECDHE key of every connection to decrypt all captured packets at a later date.
aorthover 8 years ago
Wow. My message to the banks: We are trying to build a more secure internet. Update your servers, libraries, etc every few years like the rest of us. You&#x27;re not special. It&#x27;s hard for all of us.
ddpover 8 years ago
The changes in TLS 1.3 are long overdue. There are some of us who argued vociferously to not include some of those bad ciphers but we were overruled, probably by the same cabal that decided to remove IPsec from mandatory-to-implement for IPv6.