OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

ekmi message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Hacker pokes new hole in secure sockets layer


http://www.theregister.co.uk/2009/02/19/ssl_busting_demo/

The interesting quote from the author of the attack, is on
the last line of page 2:

---
Marlinspike, who in 2002 demonstrated a separate https-busting tool 
called SSLSniff, said he sees no viable fix for the vulnerability, which 
he adds can be exploited in several additional ways he has yet to disclose.

"The ultimate solution," he said, "is to encrypt everything."
---

Arshad Noor
StrongAuth, Inc.


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]