|
|
|
|
|
by catlifeonmars
1535 days ago
|
|
> In contrast decrypting data an adversary sent to you might reveal something, especially if you can be persuaded (as happened for HTTPS with older TLS versions and most popular implementations) to tell the adversary what happened when you tried so this will usually be dangerous and a rationale for why it's safe must be thorough if we want non-experts to do it. What exactly happened for HTTPS with older TLS versions? Sounds like you’re alluding to some sort of oracle attack. |
|
It's fuzzy, perhaps somebody will remind me of the specifics.