Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hence the 'maybe'. But what information would actually be leaked by knowing the generation software (assuming it's decoupled from the server software)? It seems if a certain implementation's keys are weak, one could simply try to exploit that over all keys. I don't need to know you're running Debian before I go scanning for those particular weak keys.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: