Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

That is a really good question! I would only be guessing at whether or not they have PFS or not. On the one hand, it leaves the past vulnerable in case a breach happened, but on the other it makes diagnosing what much harder in cases like this.


Actually now I'm not sure if heartbeats are encrypted:

"It is irrelevant whether your system can even support some of the cipher suites in the list, because the Heartbeat request that triggers the vulnerability is sent before any encryption takes place."

http://www.hut3.net/blog/cns---networks-security/2014/04/14/...


Interesting. So this leads me to believe that they do record every packet.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: