Ask HN: What's the purpose of the "payload" in SSL TLS/DTLS Heartbeat anyway?

https://news.ycombinator.com/item?id=7558227
by JoelJacobson • 12 years ago
14 10 12 years ago

Having read through RFC 6520, I don't understand why the payload is necessary. Neither the server nor the client appears to be using it for anything?

Wouldn't it have been simpler and more secure to skip the payload altogether?

In a security protocol it seems strange the designers of the protocol opted for a more complex protocol than necessary.

Related Stories

Loading related stories...

Source preview

news.ycombinator.com