2

According to the Diffie-Hellman key exchange get affected by logjam, and openID uses this to establish an association. So how this going to affect OpenID?

Jens Erat
  • 24,566
  • 12
  • 82
  • 103
Thanuja
  • 123
  • 2

1 Answers1

2

logjam is not (even remotely) a break of the Diffie-Hellman key exchange method. It is a weakness of the TLS protocol. It affects only sessions, not credentials. It will soon be fixed. I estimate zero impact on OpenID. The "bad guys" cannot do MITM, only governments and ISPs could (in principle) do MITM.

Atsby
  • 1,148
  • 8
  • 6