|
@marcan42 | |||||
|
And by the way, the fact that I had to come out and make this explanation is *yet again* another example of the sorry state of tech security reporting, by both media and infosec folks themselves.
Like every single article about this bug is wrong and makes no sense. twitter.com/marcan42/statu…
|
||||||
|
||||||
|
Hector Martin
@marcan42
|
17. sij |
|
I don't understand how everyone is falling into the trap of talking about "validating" ECC params or using the wrong ones or whatever, and completely handwaving the way this actually works. If you *think* about how this should work, it doesn't make sense.
|
||
|
|
||
|
Hector Martin
@marcan42
|
17. sij |
|
It just goes on to show that in the absence of detailed official information, people are perfectly happy to make up an explanation without never mind verifying it, but not even trying to see if it is consistent or reasonable!
This is wrong.
|
||
|
|
||