YAY! HTTPS/TLS/SSL gone fishing

I guess it was just a matter of time before someone clever would come up with ways to take control over TLS/SSL connections, and here it is. ZDNet and DarkReading have stories around the flaw, and here is the work presentation with examples. Now we just have to wait for the massive patching nights.

Update: 2010-01-12 IETF has approved the draft, and coders have an official GO to implement patches for deployment in a larger scale.

Comments

Popular posts from this blog

Overhead lines

R.I.P. Google Reader

Sweden 2 Australia