Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

People might turn on EDH and then decide it's too expensive, or if they come under attack, they can easily configure it off again.

Unlike, say, the new mandatory 2048 bit RSA key length requirements.



Seems like a lot of folks missed the section of the post explaining their implementation and use of _ECDHE_ not _EDH_. The performance impact of ECDHE is surprisingly small.


It doesn't help that Apache has a setting "kEDH - Ephemeral (temp.key) Diffie-Hellman key exchange (no cert)" and "EDH - all ciphers using Ephemeral Diffie-Hellman key exchange" that (I think) maps to what IETF TLS calls "DHE - Ephemeral DH".

I get these confused all the time, and now they add in an "EC" prefix!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: