Hacker News new | ask | show | jobs
by MajesticHobo 3604 days ago
Uh, no. Implementation bugs don't mean a protocol is broken.
1 comments

Uh, good luck convincing anyone that April 2014 does anything other than demonstrate there are exactly zero reliable implementations of TLS. If the most widely used implementation can demonstrate that level of incompetence, what chance do any of the others have.

And I don't care if pointing that out costs me mod points. Its seems on these types of conversations negative points are a mark of honesty.

If there are exactly zero reliable implementation of TLS, then these 10 BTC should be easy to collect: https://ownme.ipredator.se/
Why would you waste an extremely valuable exploit on a bounty worth under $6000 USD?
It’s not clear to me that an exploit of a vulnerability in a not-widely-used TLS implementation in native OCaml (or a vulnerability in any of the other software in use on that system) would be more valuable than the bounty offered.