<?xml version='1.0' encoding='utf-8' ?>

<rss version='2.0' xmlns:lj='http://www.livejournal.org/rss/lj/1.0/' xmlns:atom10='http://www.w3.org/2005/Atom'>
<channel>
  <title>pvaneynd</title>
  <link>https://pvaneynd.dreamwidth.org/</link>
  <description>pvaneynd - Dreamwidth Studios</description>
  <lastBuildDate>Fri, 06 Nov 2009 06:21:43 GMT</lastBuildDate>
  <generator>LiveJournal / Dreamwidth Studios</generator>
  <lj:journal>pvaneynd</lj:journal>
  <lj:journaltype>personal</lj:journaltype>
  <image>
    <url>https://v2.dreamwidth.org/7693145/447974</url>
    <title>pvaneynd</title>
    <link>https://pvaneynd.dreamwidth.org/</link>
    <width>76</width>
    <height>100</height>
  </image>

<item>
  <guid isPermaLink='true'>https://pvaneynd.dreamwidth.org/131516.html</guid>
  <pubDate>Fri, 06 Nov 2009 06:21:43 GMT</pubDate>
  <title>usable attack against https found</title>
  <link>https://pvaneynd.dreamwidth.org/131516.html</link>
  <description>They discovered a &quot;Man In The Middle&quot; attack again &lt;a href=&quot;http://en.wikipedia.org/wiki/Transport_Layer_Security&quot;&gt;TLS&lt;/a&gt; (or the older SSL): during renegotiation one can insert data into the stream. See this excellent article for an &lt;a href=&quot;http://www.sslshopper.com/article-ssl-and-tls-renegotiation-vulnerability-discovered.html&quot;&gt;example&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The good part is that this requires that you can intercept the traffic between you and the server. The bad news is that this is relatively easy to do in many environments (public wifi, PC&apos;s on a hub/cheap switch etc). The &lt;b&gt;major&lt;/b&gt; bad news is that this is not an implementation bug but an error in the specification, so expect &lt;b&gt;everybody who uses SSL/TLS&lt;/b&gt; to be vulnerable and to update their products...&lt;br /&gt;&lt;br /&gt;Interesting times indeed.&lt;br /&gt;&lt;br /&gt;&lt;img src=&quot;https://www.dreamwidth.org/tools/commentcount?user=pvaneynd&amp;ditemid=131516&quot; width=&quot;30&quot; height=&quot;12&quot; alt=&quot;comment count unavailable&quot; style=&quot;vertical-align: middle;&quot;/&gt; comments</description>
  <comments>https://pvaneynd.dreamwidth.org/131516.html</comments>
  <category>security</category>
  <lj:mood>bouncy</lj:mood>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
</channel>
</rss>
