Message 267705 - Python tracker (original) (raw)

Larry -

I see at least two issues here, although they are related:

Possible resolutions:

Possible resolutions:

I see these largely as policy decisions rather than technical ones. The security implications of the first issue are fairly small (I would be interested in PSRT's assessment of an actual attack on a predictable hash secret); of the second issue rather larger and probably unquantifiable.