Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
TallGuyShort
on Sept 22, 2016
|
parent
|
context
|
favorite
| on:
An Important Message About Yahoo User Security
The other possibility is somehow intercepting them between SSL termination and hashing.
perfectfire
on Sept 22, 2016
[–]
That's a good point. If they got ahold of Yahoo's cert key they could even grab passwords before SSL termination.
schoen
on Sept 23, 2016
|
parent
[–]
Not passively anymore: login.yahoo.com is negotiating PFS ciphersuites which the private key can't decrypt without a copy of the ephemeral ECDHE parameters.
Consider applying for YC's Fall 2026 batch!
Applications
are open till July 27.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: