4 ms·
That's a good point. If they got ahold of Yahoo's cert key they could even grab passwords before SSL termination.
by perfectfire 10y ago
That's a good point. If they got ahold of Yahoo's cert key they could even grab passwords before SSL termination.
- schoen 10y agoNot passively anymore: login.yahoo.com is negotiating PFS ciphersuites which the private key can't decrypt without a copy of the ephemeral ECDHE parameters.