Live data from Hacker News

Viewing profile — syzzer

syzzer

HN member
Joined
Thu, Mar 20, 2014, 12:01 AM UTC
HN karma
12
Public activity
8 items

About syzzer

No profile information was provided.

Recent public activity

  1. comment
    Comment #26524997

    > Upload a package to PyPI or Node.js that emits specially crafted console output as part of its installer. If someone runs my installer without checking the contents, why would I …

  2. comment
    Comment #9860337

    Note that this is specifically OpenVPN on Windows, since the Windows installers ship with their own openssl dll (and as already said by the other commenter, a new installer was mad…

  3. comment
    Comment #9575507

    Thanks for elaborating. The 'other side' are the people currently working on the negotiated-ffdhe draft (which I assume are bright people too). The draft was last updated a week ag…

  4. comment
    Comment #9575166

    I strongly believe in 'Audi alteram partem', and like to understand rather than believe. Hence my question. For all I know, a few extra bits parameter length can make the NFS just …

  5. comment
    Comment #9575092

    > It's not particularly surprising to the IETF TLS Working Group either, which is at least partially why https://tools.ietf.org/html/draft-ietf-tls-negotiated-ff-dhe... . exists. T…

  6. comment
    Comment #7852198

    You don't need another layer of encryption, just another layer of authentication protects you from attacks that require an active mitm adversary (as basically all attacks on TLS do…

  7. comment
    Comment #7599837

    You should do that for all your vulnerable peers (i.e. clients too), and restart the daemon to make it load the updated library. Then generate new keys for all of them. While there…

  8. comment
    Comment #7550145

    Yes, this has been introduced in the original heartbeat extension commit (01-01-2012): http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=bd69...