Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Apparently implementing CBC correctly is too complex to do right:

https://www.imperialviolet.org/2013/10/07/chacha20.html



No, that's not what he's saying. He's saying that making the TLS CBC constructions secure is hard. They were designed in the 1990s. Making a CBC implementation secure today is much easier.


Indeed, just about every brand of SSL load balancer was doing it wrong:

https://www.imperialviolet.org/2014/12/08/poodleagain.html




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: