in my opinion, it can't be. if all the traffic are sniffed and logged, why can't the entire encrypted messaged get replayed and decrypted by those who want to? prove me right.
Quote from NoMoreOptions:
in my opinion, it can't be. if all the traffic are sniffed and logged, why can't the entire encrypted messaged get replayed and decrypted by those who want to? prove me right.
Quote from lilboy716:
SSL uses public key encryption algorithm to exchange a symetric session key. then the symetric sessoin key is used for the rest of the session.
nothing is safe 100% that's why you see many new encryption algoirthms coming onto mainstream market. DES 56bits used to be the standard, it was infeasible to crack it back in the days because of limited computing power. now even 128bits can be cracked by a computer farm in matter of days. currently the move is towards 1024. It's a matter of time before computing power catchs up and made 1024 obsolete.
most keys issued by trusted authorities like versign is 256. you can, however generate keys with 1024bits key length and use it on your own webserver.