Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If the default entropy source on those platforms was actually inadequate in any way, it would have the everliving fuck exploited out of it, at levels far below their product. Nobody gives a shit about HTTPS seed quality if the entire TCP stack is compromised!

They should be excoriated for delivering a massive (and pointless) performance regression to their users with the slowest computers. Every time they pull shit like this, it just means that fewer users will upgrade, not just now but in the future.



It's actually the opposite; you use TLS exactly because you're not supposed to trust the TCP stack.

But your basic point holds. There's lots of Win2k deployed in sensitive production locations, and if they didn't have secure random numbers, we'd have bigger problems than Firefox.


I thought I used TLS because I didn't want my sensitive data going over the wire in plaintext.


"we'd have bigger problems than Firefox"

It's not like win2K is super-secure...

Seriously, it _really_ scares me when I see medical equipment running any Windows (not only win2k or earlier) being networked in hospitals.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: