[pro] Heartbleed?
Max Rottenkolber
max at mr.gy
Thu Apr 24 17:04:23 UTC 2014
On Thu, 24 Apr 2014 18:13:35 +0200, Pascal J. Bourguignon wrote:
> a dead process sending fixed or previsible packets
I didn't think of that. So basically you ensure the responding connection
isn't compromised by exercising the encryption, which is the hardest to
fake for a malicious attacker. Makes sense... Shame on me! :)
What about a fixed length input though (and maybe answering with a
digest)? It still seems to me that the specified behavior is overly
arbitrary/error prone.
More information about the pro
mailing list