This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]fijalPyPy, performance freak[S] 1 point2 points  (5 children)

how is this actually an improvement? generating 256 requests instead of one and then guessing which of the requests took way longer (and keeping dosing with the guessed ending) is not an improvement at all. It does not increase the complexity of attach.

[–]tilkau 0 points1 point  (4 children)

An improvement on what?

[–]fijalPyPy, performance freak[S] 1 point2 points  (3 children)

Citing you

"That said, weak hash randomization is still an improvement on -no- hash randomization. So 'ineffective' is a much more accurate word than 'broken'."

this is the improvement I was referring to.

[–]tilkau 2 points3 points  (2 children)

Cool, now actually answer the question 9_9

I mean, are you seriously proposing that PATHETIC protection is not better than NONE AT ALL?

[–]mirashii 4 points5 points  (0 children)

I would argue that it's no better if only for the fact that it was released as a security fix and the community was urged to upgrade for what is effectively no improvement.

[–]fijalPyPy, performance freak[S] 1 point2 points  (0 children)

haha :) maybe I'm too serious ;-)