3 ms·
Cool – hadn't heard of that before. I was thinking more along the lines of a purely server-side approach: $_REQUEST["salted_SHA_hash_of_symmetric_TLS_key"]
by neftaly 12y ago
Cool – hadn't heard of that before. I was thinking more along the lines of a purely server-side approach:
$_REQUEST["salted_SHA_hash_of_symmetric_TLS_key"]
You'd save the current key to a DB, and manually check it in future requests.
- Mawaai 12y agoWell, if you can intercept the request to the server to can also change that parameter of the TLS certificate hash.
- deleted 12y ago[deleted]
- neftaly 12y agoIs that actually true, though (especially w.r.t. Forward Secrecy)? Don't both parties generate separate halves of a symmetric key independently, preventing any one party from forcing the use of a particular key on a new session?