Hacker News new | ask | show | jobs
by hedora 2006 days ago
I wasn’t referring to the cryptosuite weakening. I was referring to unnecessary complexity in the SSL protocol itself, such as the whole certificate chain parsing mess, the countless opportunities to implement things vulnerable to downgrade attacks, and the overly-broad attack surface of the whole thing.