Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I mean as mentioned in the article, it happened at Twitter. And what about Heartbleed-style issues?


It happened at Twitter, was discovered internally at Twitter, remediated at Twitter, and disclosed by Twitter. It was talked about but not in any apparent way felt. And, again, if that's your only concern, there are simpler ways to mitigate that threat than a whole PAKE.

PAKEs don't address Heartbleed-like issues; in fact, they create more opportunities for them.


How's that?


More protocol mechanism => more code => more memory disclosure bugs. That's literally how Heartbleed happened, and in a crypto protocol, no less.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: