TCH ECO SA Sakshi Pharande We Thought AES-256 Was Enough. Then We Found a Bigger Problem. A real Spring Boot fintech backend story about static keys, ECDHE, and why encryption alone is not enough.
LI LI Daobing [闲谈RFC] 19: RFC 8446 — TLS 1.3 为什么要淘汰DHE 在 TLS 1.2 (RFC 5246)时代,我们有三种方法来交换密钥,一种是最经典的 RSA,它的最主要问题是缺乏前向安全。第二种是 DHE ,这个算法的引入目的就是提供前向安全。第三种是 ECDHE,其中EC就是大家常说的椭圆曲线。而在 TLS 1.3 (RFC…