-
-
Notifications
You must be signed in to change notification settings - Fork 33.9k
Closed
Labels
cryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.securityIssues and PRs related to security.Issues and PRs related to security.tlsIssues and PRs related to the tls subsystem.Issues and PRs related to the tls subsystem.
Description
based on the recent paper on new attacks against diffie-hellman it might be a good idea to remove 2 of the well known primes that node comes with from the defaults, namely modp1 and modp2 aka Oakley Group 1 and 2 which are mentioned specifically in the linked paper as being vulnerable to pre computation attacks with academic and state level resources respectively.
Metadata
Metadata
Assignees
Labels
cryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.securityIssues and PRs related to security.Issues and PRs related to security.tlsIssues and PRs related to the tls subsystem.Issues and PRs related to the tls subsystem.