4 ms·
... and are not using authenticated encryption as you should.
by devit 11y ago
... and are not using authenticated encryption as you should.
- djb_hackernews 11y agoIn my experience, there is a bit of hardware (which was the root cause in the articles case) between SSL termination and application servers. So even using encryption, you are still vulnerable.
- tyingq 11y agoIn many situations, you might still have unencrypted traffic, even if your app is using authenticated encryption. Like, for example, if you're doing DNS lookups, or syslog to a remote host, etc.
- deleted 11y ago[deleted]