A full disclosure is scheduled for Friday September 23rd at the Ekoparty conference. Note that this only affects SSL 2.0 and TLS 1.0; unfortunately most web servers are misconfigured to still accept SSL 2.0, and TLS 1.1 and 1.2 have seen limited deployment. The practicality of the attack remains to be determined (for one it isn't very fast, but if the intent is just to decrypt the data for later use that isn't an impediment).
Read more of this story at Slashdot.
No comments:
Post a Comment