|
|
|
|
|
by cperciva
1464 days ago
|
|
It's possible that I could have taken TLS 1.1 and removed all the broken parts, sure. I mean, that's pretty much what TLS 1.3 is. But frankly I trust my ability -- both now and in 2007 -- to use standard cryptographic algorithms to build a new protocol far more than I trust my ability to remove all the crap from TLS 1.1. (Did you deliberately not mention heartbleed?) |
|
The threshold question is, "could this vulnerability be reasonably expected to recur in independent implementations of the protocol?"
As for stripping back TLS 1.1 --- it wouldn't take much more than simply picking a single ciphersuite and requiring TLS 1.1. You wouldn't need to know, for instance, about export ciphers.