4 ms·
SerenityOS has implemented its own TLS 1.2 client from scratch (no server side support so far), currently with TLS_RSA_ and TLS_DHE_RSA_ only, and AES-CBC and A
by wolf550e 5y ago
SerenityOS has implemented its own TLS 1.2 client from scratch (no server side support so far), currently with TLS_RSA_ and TLS_DHE_RSA_ only, and AES-CBC and AES-GCM only (software table driven AES, software GCM, naive CBC padding handling, nothing is constant time).
It does not even pretend to be secure so far (intentionally accepts self signed certs), but if they ever want to make it secure, that would be a big task.
For compatibility, they really should implement ECDHE with NIST P-256, because that is what most of the internet uses and what they support means they always fallback to no-PFS.
https://github.com/SerenityOS/serenity/tree/master/Userland/Libraries/LibTLS https://github.com/SerenityOS/serenity/tree/master/Userland/...
https://github.com/SerenityOS/serenity/tree/master/Userland/Libraries/LibCrypto https://github.com/SerenityOS/serenity/tree/master/Userland/...