Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You are correct. They never fixed issues #2, #3, and #6 (as stated under "Vendor response".) Any half decent resolver properly randomizes both ports and txid not using the predictable libc random(), but nginx developers have staunchly refused to do so...


Thanks for posting this publicly!

I suggest updating your post to say that the issues are still unfixed as of today's date.


Done.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: