3 ms·
It maxes has been maxing out my laptop CPU for an inordinate amount of time for years as well. These "financial secrets" are emailed in the clear after every tr
by beachaccount 15y ago
It maxes has been maxing out my laptop CPU for an inordinate amount of time for years as well. These "financial secrets" are emailed in the clear after every transaction, so your point is moot.
Burgerbrain: PayPal.com, CitiCards.com, 2checkout.com, and many payment processors all use RC4-SHA or AES256-SHA. You are wrong.
- burgerbrain 15y agoTheir patchy security doesn't render his argument invalid. Edit: beachaccount: Financial institutions not using DHE is not a logically sound counter to "There's nothing wrong with using DHE algorithms, particularly if you're going to be transferring financial secrets around." While those institutions may chose not to, there is nothing wrong with others choosing otherwise. Additionally, patchy security on the part of one operator certainly is not a logically sound argument against this. Furthermore, in the future, actually reply to a post in order to reply to a post. Not doing so unnecessarily confuses the flow of conversations (posts are not scarce resources).
- tptacek 15y ago"Patchy security"? What are you on about?
- burgerbrain 15y agoI'm refering to the portion of the comment I was responding to: "These "financial secrets" are emailed in the clear after every transaction" The implication being that since they were sending the information in the clear in a separate part of their system, that they were wrong in configuring their https site as they did. I object to that conclusion.
- tptacek 15y agoAh. Patchy works there. I'm sorry about that. Having a hairtrigger day.
- burgerbrain 15y agoNo worries!
- beachaccount 15y agoNo, that indicates that these were not actually financian secrets, hence the quotes.
- burgerbrain 15y agoI'm going to go ahead and give the developers of the particular site the benefit of the doubt and not you, if you don't mind. Furthermore, one particular site using https in a particular mode when they don't need to use https at all is still not a logical argument against other sites using https with those ciphers.