3 ms·
Many https sites use RC4, I wouldn't be so sure.
by hcf 11y ago
Many https sites use RC4, I wouldn't be so sure.
- netheril96 11y agoThen use a browser that rejects RC4 (like latest Chrome).
- deleted 11y ago[deleted]
- Robin_Message 11y agoThe private key is used to negotiate a session key, which is then used as the symmetric key for RC4 or whatever stream or block cipher you are using. Those session keys are ephemeral and per-session, so leaking them is only a problem for those sessions. (Also, since it's a stream cipher, it can't use the same key ever again, else you can xor those ciphertexts to get 2 xored plaintexts, which are much easier to crack.)