5 ms·
From Adam Langley, who works at Google on their SSL stack, on his post "How to botch TLS forward secrecy": In the case of multiplicative Diffie-Hellman (i.e. D
by jamesvl 13y ago
From Adam Langley, who works at Google on their SSL stack, on his post "How to botch TLS forward secrecy":
In the case of multiplicative Diffie-Hellman (i.e. DHE), servers are free to choose their own, arbitrary DH groups. <snip> ... it's still the case that some servers use 512-bit DH groups, meaning that the connection can be broken open with relatively little effort.
Full article of his at https://www.imperialviolet.org/ https://www.imperialviolet.org/
- danielparks 13y agoFor posterity: https://www.imperialviolet.org/2013/06/27/botchingpfs.html https://www.imperialviolet.org/2013/06/27/botchingpfs.html