Rick Welykochy rick at praxis.com.au
Wed Nov 24 06:40:14 AEDT 2010

Martin Barry wrote:

> - existing sessions could have, and appear to have, kept working during the
>    leak. Unencrypted traffic transmitted during this time is obviously
>    vulnerable.

I don't understand how a TCP session (i.e. stream) could live for
very long if there is not a receiving end to the socket. Once the
TCP send window is exhausted, doesn't the stream stall waiting for
ACKs? No ACK, no stream AFAIK.


