Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×
Security

Man-In-the-Middle Vulnerability For SSL and TLS 170

imbaczek writes "The SSL 3.0+ and TLS 1.0+ protocols are vulnerable to a set of related attacks which allow a man-in-the-middle (MITM) operating at or below the TCP layer to inject a chosen plaintext prefix into the encrypted data stream, often without detection by either end of the connection. This is possible because an 'authentication gap' exists during the renegotiation process, at which the MitM may splice together disparate TLS connections in a completely standards-compliant way. This represents a serious security defect for many or all protocols which run on top of TLS, including HTTPS."

Comment Yet another "celebrity exec to blame" article (Score 1) 603

All this furore over Jobs, Gates and Ballmer. It's as if these guys are working 6000 hours a week, making every minor decision. There are lots and lots of talented people working "behind the scenes" to advise on the right technological directions to pursue.

Furthermore, whoever wrote this has obviously never come across a geek-ran company, strangling under quite significant business blindspots. As a company gets larger, wIth the right advisers, the guy at the top should be the business man. Sure, if he's a complete technological disaster, there's a problem, but I don't think there's too big of an issue when you've nearly tripled in net worth.

Articles like these, they're just the business version of a "music critic". Another version of the gossip column.

Comment Agreed (Score 1, Funny) 176

Growing up, I knew several families who restricted their kids from watching The Simpsons. I think those type of standards are sorely lacking thesedays and we should use them as positive examples to reassert control. Now they've got the twitters, these children are beginning to secretly rape themselves.

Slashdot Top Deals

The Tao is like a glob pattern: used but never used up. It is like the extern void: filled with infinite possibilities.

Working...