[Full-disclosure] JaPCrypt
coderman
coderman at gmail.com
Wed Feb 6 11:59:30 GMT 2008
On Feb 6, 2008 3:21 AM, Gerardo Di Giacomo <gerardo at linux.it> wrote:
> ...
> The PSK is never sent, neither by the client neither by the server.
apologies, i will be more clear:
since psk without key distribution nor secure secret exchange does not
solve the problems that HTTPS solves, to say this is useful in
situations where HTTPS is not available is disingenuous.
Full-Disclosure is hosted and sponsored by Secunia.