4 ms·
Thanks for the kind words! It's humbling to have a security pro like you even read it :). I dabble with this stuff because I find it interesting (especially the
by moserware 17y ago
Thanks for the kind words! It's humbling to have a security pro like you even read it :). I dabble with this stuff because I find it interesting (especially the number theory). The Wireshark'ing was to see how things really worked.
Hopefully the links I made to the Netscape and Debian OpenSSL RNG fiascos along with at least some coverage of how many subtle checks the handshake performs terrifies people enough to follow the exhortation I put at the end: "It's certainly better to use TLS than inventing your own solution."
- tptacek 17y agoMost developers would probably find Crypt++'s implementation of RSA verification --- or even, gag, LibTomcrypt --- a better rundown of how to do this safely. Too much of Mozilla NSS's functionality is scattered across multiple modules and indirected through function pointers.
- spicyj 17y agoForgive my naïvety, but what's wrong with LibTomCrypt? And did you mean Crypto++?