TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Tor and the BEAST SSL attack

59 pointsby xtacyover 13 years ago

2 comments

throwaway32over 13 years ago
Slightly OT, but this is a perfect reason to regard javascript crypto as dangerous. If one of the most heavily scrutinized cryptographic protocols can have what is in retrospect, a fairly obvious flaw (WEP fell to a very similar predictable IV attack), the average developer does not stand a chance of getting it right implementing it from scratch in an environment they do not have strong control over.
评论 #3033795 未加载
anon1385over 13 years ago
Nothing to worry about:<p><a href="http://news.ycombinator.com/item?id=3015995" rel="nofollow">http://news.ycombinator.com/item?id=3015995</a> <i>I happen to know the details of this attack since I work on Chrome's SSL/TLS stack.</i> <i>Fundamentally there's nothing that people should worry about here. Certainly it's not the case that anything is 'broken'.</i>
评论 #3033785 未加载
评论 #3033670 未加载