3 ms·
Are you worried about parts of the TLS handshake being intercepted, or something? Because even then that's non-sensitive information like public keys and cipher
by mkinitcpio 12y ago
Are you worried about parts of the TLS handshake being intercepted, or something? Because even then that's non-sensitive information like public keys and cipher lists and stuff, no? Or are we worried about side-channel attacks, or weak ciphers being chosen?
Just curious about your reasoning for why TLS alone isn't sufficient.
- marcosdumay 12y agoHe's probably worried about those places looking at the sites he connects to, data sizes and other kinds of metadata. But also, there are plenty of sites around with broken TLS that can be intercepted by a man in the middle.