Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

TLS 1.0 uses chained IVs, which is a protocol flaw. It also has an explicit protocol alert for decryption failures, which makes error oracle attacks simpler. TLS 1.0 is broken. It isn't catastrophically broken so far as we know now, but nobody should be deliberately preferring it.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: