4 ms·
This seems like rather a waste of user and processor time. While the Debian OpenSSL disaster is both hilarious and embarrassing, the impact on the end user is m
by jamess 18y ago
This seems like rather a waste of user and processor time. While the Debian OpenSSL disaster is both hilarious and embarrassing, the impact on the end user is more or less non-existent.
For one thing, in path attacks not on the local network are more or less impossible. Even if you're talking to a server which has a weak key, the chances that your data will be compromised is small.
Second, nowhere that collects important details is going to have a weak key. This is Debian we're talking about. This is not a distribution that is used by a many online retailers. Even if it was, anywhere you're likely to trust is going to be using TLS offload cards anyway, which have hardware secure random number generators.
Third, anywhere you'd trust with important personal details has already reacted and generated new keys. If the people you're dealing with aren't keeping up with high publicity security advisories sure as hell aren't keeping up with much lower profile advisories. This will tend to mean you are far more at risk from the server itself being compromised, rather than any communication in progress.