Comment on OpenSSL Security Advisory: TLS heartbeat read overrunparentComments−drdaeman12yBut isn't spiped mostly irrelevant here?I mean, it's not a TLS replacement, as it's based on PSK (thus only useable between two mutually trusting peers like me and myself), not PKI.−cperciva12yspiped should be irrelevant here. But there are a lot of people using PKI where they could be using PSK.−otterley12yWho, exactly? Distributing shared secrets securely is a non-trivial exercise.−tripzilch12yYou mean like wifi-passwords? :) Everybody seems to manage distributing those just fine?
Comments
But isn't spiped mostly irrelevant here?
I mean, it's not a TLS replacement, as it's based on PSK (thus only useable between two mutually trusting peers like me and myself), not PKI.
spiped should be irrelevant here. But there are a lot of people using PKI where they could be using PSK.
Who, exactly? Distributing shared secrets securely is a non-trivial exercise.
You mean like wifi-passwords? :) Everybody seems to manage distributing those just fine?