Hacker News new | ask | show | jobs
by briansmith 11 days ago
Just to be clear, OpenSSL isn't doing the wrong thing, based on the description in the blog post. The specification allows and even requires behavior similar to that.