3 ms·
What are the hashes of? :D
by n00body 10y ago
What are the hashes of? :D
- tptacek 10y agoShort strings describing crypto bugs. So when you find something I didn't, I can't claim to have found it myself first.
- n00body 10y agoNo padding used for keys sent by client? Public Key sent by server not verified by client? Keys sent by client are not verified by server? I suspect there are whole heap of problems wrong with this but thats just what i see atm.
- tptacek 10y ago1. Yep, that's one of my issues (echo unpadded rsa | openssl sha -sha256) 2. That's an issue but I didn't count it because the blog post cops to that problem.