Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

PFS is just one of many desirable properties, and getting access to plaintext is just one of many kinds of threat. Getting access to ephemeral keys and other sensitive state can enable session hijacking. It's still not a great example, though, because it doesn't illustrate that threat model either.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: