Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I disagree that I'd make similar decisions. Postel's Law is a big part of the reason Bleichenbacher attacks (adaptive chosen-ciphertext attacks)[1] stayed so common for so long. As an engineer responsible for the security I absolutely reject malformed inputs.

https://en.wikipedia.org/wiki/Adaptive_chosen-ciphertext_att...



But that's what I'm saying; Postel may well have ALSO rejected malformed inputs in this particular case.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: