@matthew_d_green Re Google and PFS, don't forget about TLS session tickets. Someone with access to those site-wide keys can subvert PFS.
@moxie @matthew_d_green Yeah but they can be disabled server-side. Does PFS require TLS sessions tickets to be turned on?
-
-
@moxie@matthew_d_green blackhat presentation on TLS session ticket security. https://media.blackhat.com/us-13/US-13-Daigniere-TLS-Secrets-WP.pdf … slides: https://media.blackhat.com/us-13/US-13-Daigniere-TLS-Secrets-Slides.pdf …Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
@inthecloud247 No, but servers that don't catch on fire do.@matthew_d_greenThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.