Hacker News new | past | comments | ask | show | jobs | submit login

Super happy that the OpenSSL team decided to be proactive and just enable `SSL_OP_SINGLE_DH_USE` for all users, as well as bump the minimum DH key size. Better defaults for everyone!



Yeah, and it looks like BoringSSL did that about a year ago :)

https://boringssl.googlesource.com/boringssl/+/9f226a5f5183e...


David's the best :-)


Interesting that the corresponding ECDH option is still disabled by default and ephemeral keys are cached.


It's about time they did. I always wondered why this was disabled by default.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: