Hacker News new | ask | show | jobs
by commandlinefan 2479 days ago
Well, TLS 1.2 still mandates PKCS 1.5:

"The RSAES-OAEP encryption scheme defined in [PKCS1] is more secure against the Bleichenbacher attack. However, for maximal compatibility with earlier versions of TLS, this specification uses the RSAES-PKCS1-v1_5 scheme." [RFC 5246, 7.4.7.1]