3 ms·
Nice, I forgot that one. BearSSL is one of only two TLS implementations (if I recall correctly) that wasn't vulnerable to the most recent Bleichenbacher attack
by throwawaymath 7y ago
Nice, I forgot that one. BearSSL is one of only two TLS implementations (if I recall correctly) that wasn't vulnerable to the most recent Bleichenbacher attack variant.
- tptacek 7y agoThat's correct, BearSSL and BoringSSL (Google's OpenSSL fork). Pornin is a bad-ass. But keep in mind that they were targeting C/C++ libraries, so we don't have telemetry on (for instance) Go's crypto/tls or whatever Rust is doing with ring.