[Cryptography] Fwd: OPENSSL FREAK

dan at geer.org dan at geer.org
Mon Apr 13 23:49:48 EDT 2015


> > A better behavioral economist than I might now work on an insurance
> > scheme whereby so long as you take the updates it is the maker that
> > is strictly liable for all downsides, else it is you.
> 
> Good idea, except when the maker starts shipping out updates that have 
> features that you don't want, e.g., surveillance.  In that case you're 
> screwed if you do (unwanted features), screwed if you don't (liability).

for all values of "solution," your choice will be a Hobson's choice

next question, please

--dan



More information about the cryptography mailing list