Skip to content

Comment on OpenSSL Security Advisory: TLS heartbeat read overrunparent

Comments

But isn't spiped mostly irrelevant here?

I mean, it's not a TLS replacement, as it's based on PSK (thus only useable between two mutually trusting peers like me and myself), not PKI.

spiped should be irrelevant here. But there are a lot of people using PKI where they could be using PSK.

Who, exactly? Distributing shared secrets securely is a non-trivial exercise.

You mean like wifi-passwords? :) Everybody seems to manage distributing those just fine?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.