YAY! HTTPS/TLS/SSL gone fishing
I guess it was just a matter of time before someone clever would come up with ways to take control over TLS/SSL connections, and here it is. ZDNet and DarkReading have stories around the flaw, and here is the work presentation with examples. Now we just have to wait for the massive patching nights.
Update: 2010-01-12 IETF has approved the draft, and coders have an official GO to implement patches for deployment in a larger scale.
Update: 2010-01-12 IETF has approved the draft, and coders have an official GO to implement patches for deployment in a larger scale.
Comments
Post a Comment