|
|
|
|
|
by javier_e06
1206 days ago
|
|
I looked at the list of take-aways and one big important take away was missing.
Testing.
If a SSL depends on generating millions of unique keys then there should be an existing test somewhere the ensures that SSL does this before the release into production. The test would have caught the initialization and send the code back for re-work, clarification. |
|
And it's completely insecure - just guess the time and you know the output.