back

by josephcsible·6y ago·view on hn ↗
My reading of this is that it only affects old, weak cipher suites that don't support forward secrecy, so only hosts that have an insecure configuration anyway are affected by this.
1 comments
Note that some implementations re-use ephemeral keys on DHE, this was one of the finding of LOGJAM, and I'm not sure if this has been fixed in every TLS libraries.

https://raccoon-attack.com/