On Sep 01, 2015, at 12:49, Eric Rescorla <e...@rtfm.com> wrote: > > As Alissa, I was wondering why it wasn’t easier to fix the one > implementation instead. > > > Because it's widely fielded, and browsers don't know in advance what > kind of server they are talking to.
The one thing I’ll add in addition to what’s in the msg to Alissa is that the time from Brian raising an issue to having testable patches to fix the issue was about two days. And, this all happened back at the end of ’13; what can I say the wheels of standardization move slowly while fixing an issue that might affect a noticeable swath of the Internet moves a little faster. spt _______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls