Skip to content

Comment on On the (provable) security of TLS: Part 1parent

Comments

On the contrary, it seems to be fairly decent timing. Since it draws attention to the issue of formal security in TLS. The formal proofs he refers to have caveats either 1) they use actually secure asymmetric crypto whereas TLS does not or 2) assume both that all parts work correctly in tandem and have some strange assumptions.

The fact that someone has vulnerability only goes to show you that we probably need to do more work both with the proofs and changing TLS so its easier to proof. This is possibly the third time that an ignored, "academic crypto issue' has broken TLS. This is of course assuming that they have a protocol flaw and not an implementation one.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.