[pro] Heartbleed?

Max Rottenkolber max at mr.gy
Thu Apr 24 17:04:23 UTC 2014


On Thu, 24 Apr 2014 18:13:35 +0200, Pascal J. Bourguignon wrote:

> a dead process sending fixed or previsible packets

I didn't think of that. So basically you ensure the responding connection 
isn't compromised by exercising the encryption, which is the hardest to 
fake for a malicious attacker. Makes sense... Shame on me! :)

What about a fixed length input though (and maybe answering with a 
digest)? It still seems to me that the specified behavior is overly 
arbitrary/error prone.






More information about the pro mailing list