Comment 3 for bug 1379132

Revision history for this message
Seth Arnold (seth-arnold) wrote :

Wow, this is really depressing.

I don't know how openvpn does session key negotiation but unless they're careful they may wind up exposing aes-256's 2^99-level-security related-key attacks. aes-128 is probably fine for the control channel and doesn't have the same related-key issues.

Thanks