[ Home ]

ssl

fx — 09 Apr 2014 07:43

Subject: ssl

what does our resident security expert think about the recent brouhaha?

grix — 10 Apr 2014 01:56

Subject: Re: ssl

Short answer - the sky is falling - flaw existed since dec 2011 in the core software that provides encryption of Internet traffic (OpenSSL) - remote attackers read memory from web server process without authentication This leaks session IDs, passwords and web server private keys for certificates - agencies who record encrypted traffic can probably now decrypt it - client software is also vulnerable (update your browser! Everyone needs to change their password for websites and other Internet services (VPNS etc). We are having a field day on the open test front but also having to defend - busy times!

grix — 10 Apr 2014 01:59

Subject: Re: ssl

Useful test for websites - extension for Chrome

Reply




Smileys


providers of synthetic therapeutic virtual-chemical-combination therapy for humans since before fuckin ages ago