Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
perfectfire
on Sept 22, 2016
|
parent
|
context
|
favorite
| on:
An Important Message About Yahoo User Security
That's a good point. If they got ahold of Yahoo's cert key they could even grab passwords before SSL termination.
schoen
on Sept 23, 2016
[–]
Not passively anymore: login.yahoo.com is negotiating PFS ciphersuites which the private key can't decrypt without a copy of the ephemeral ECDHE parameters.
Consider applying for YC's Summer 2026 batch! Applications are open till May 4
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: