<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Another Protocol Bites The Dust</title>
	<atom:link href="http://www.links.org/?feed=rss2&#038;p=780" rel="self" type="application/rss+xml" />
	<link>http://www.links.org/?p=780</link>
	<description>Ben Laurie blathering</description>
	<lastBuildDate>Fri, 27 Aug 2010 13:41:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Links &#187; TLS Renegotiation, 7 Months On</title>
		<link>http://www.links.org/?p=780&#038;cpage=1#comment-367103</link>
		<dc:creator>Links &#187; TLS Renegotiation, 7 Months On</dc:creator>
		<pubDate>Wed, 09 Jun 2010 08:18:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.links.org/?p=780#comment-367103</guid>
		<description>[...] been 7 months since the TLS renegotiation problem went public and Opera&#8217;s security group have a couple of interesting articles about it. The [...]</description>
		<content:encoded><![CDATA[<p>[...] been 7 months since the TLS renegotiation problem went public and Opera&#8217;s security group have a couple of interesting articles about it. The [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Links &#187; Extended Subsets</title>
		<link>http://www.links.org/?p=780&#038;cpage=1#comment-344067</link>
		<dc:creator>Links &#187; Extended Subsets</dc:creator>
		<pubDate>Thu, 17 Dec 2009 16:38:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.links.org/?p=780#comment-344067</guid>
		<description>[...] dealing with the recent SSL fun, I met Marsh Ray, who found the problem in the first place. Marsh has a website, [...]</description>
		<content:encoded><![CDATA[<p>[...] dealing with the recent SSL fun, I met Marsh Ray, who found the problem in the first place. Marsh has a website, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 78% of most popular HTTPS are still vulnerable &#171; onlinesecurityblog.info</title>
		<link>http://www.links.org/?p=780&#038;cpage=1#comment-341298</link>
		<dc:creator>78% of most popular HTTPS are still vulnerable &#171; onlinesecurityblog.info</dc:creator>
		<pubDate>Thu, 03 Dec 2009 17:28:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.links.org/?p=780#comment-341298</guid>
		<description>[...] Laurie of Google was working on the renegotiation flaw around six weeks before it was made public, so it is perhaps unsurprising that 7 of the 24 safe sites are owned by [...]</description>
		<content:encoded><![CDATA[<p>[...] Laurie of Google was working on the renegotiation flaw around six weeks before it was made public, so it is perhaps unsurprising that 7 of the 24 safe sites are owned by [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: операционные системы Linux/BSD &#187; В протоколах SSL/TLS найдена критическая уязвимость</title>
		<link>http://www.links.org/?p=780&#038;cpage=1#comment-337586</link>
		<dc:creator>операционные системы Linux/BSD &#187; В протоколах SSL/TLS найдена критическая уязвимость</dc:creator>
		<pubDate>Wed, 11 Nov 2009 06:52:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.links.org/?p=780#comment-337586</guid>
		<description>[...] реализаций протокола. Для OpenSSL уже выпущен временный патч (дополнение: исправления представлены в GnuTLS 2.8.5 и OpenSSL [...]</description>
		<content:encoded><![CDATA[<p>[...] реализаций протокола. Для OpenSSL уже выпущен временный патч (дополнение: исправления представлены в GnuTLS 2.8.5 и OpenSSL [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NetStorming &#187; Seria vulnerabilidad en SSL</title>
		<link>http://www.links.org/?p=780&#038;cpage=1#comment-337095</link>
		<dc:creator>NetStorming &#187; Seria vulnerabilidad en SSL</dc:creator>
		<pubDate>Sun, 08 Nov 2009 01:50:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.links.org/?p=780#comment-337095</guid>
		<description>[...] un post en Slashdot, una grave vulnerabilidad en el protocolo SSL podría permitir ataques de man-in-the-middle durante [...]</description>
		<content:encoded><![CDATA[<p>[...] un post en Slashdot, una grave vulnerabilidad en el protocolo SSL podría permitir ataques de man-in-the-middle durante [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fallo de seguridad SSL y TLS &#124; El mundo de IMD</title>
		<link>http://www.links.org/?p=780&#038;cpage=1#comment-337033</link>
		<dc:creator>Fallo de seguridad SSL y TLS &#124; El mundo de IMD</dc:creator>
		<pubDate>Sat, 07 Nov 2009 14:46:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.links.org/?p=780#comment-337033</guid>
		<description>[...] en Slashdot una noticia que se está extendiendo como la pólvora: se trata de una vulnerabilidad bastante seria en SSL. Resumidamente, se trata de un clásico man-in-the-middle que podría explotar la renegociación de [...]</description>
		<content:encoded><![CDATA[<p>[...] en Slashdot una noticia que se está extendiendo como la pólvora: se trata de una vulnerabilidad bastante seria en SSL. Resumidamente, se trata de un clásico man-in-the-middle que podría explotar la renegociación de [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: В протоколах SSL/TLS найдена критическая уязвимость &#187; Боталка</title>
		<link>http://www.links.org/?p=780&#038;cpage=1#comment-337025</link>
		<dc:creator>В протоколах SSL/TLS найдена критическая уязвимость &#187; Боталка</dc:creator>
		<pubDate>Sat, 07 Nov 2009 12:11:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.links.org/?p=780#comment-337025</guid>
		<description>[...] реализаций протокола. Для OpenSSL уже выпущен временный патч, середыш которого сводится к пoлнoму отключению [...]</description>
		<content:encoded><![CDATA[<p>[...] реализаций протокола. Для OpenSSL уже выпущен временный патч, середыш которого сводится к пoлнoму отключению [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Barrapunto &#124; Descubierta grave vulnerabilidad en SSL/TLS &#171; El camello, el Leon y el niño. O la evolución del perro al lobo</title>
		<link>http://www.links.org/?p=780&#038;cpage=1#comment-337020</link>
		<dc:creator>Barrapunto &#124; Descubierta grave vulnerabilidad en SSL/TLS &#171; El camello, el Leon y el niño. O la evolución del perro al lobo</dc:creator>
		<pubDate>Sat, 07 Nov 2009 10:50:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.links.org/?p=780#comment-337020</guid>
		<description>[...] cuenta: «Leo en Slashdot una noticia que se está extendiendo como la pólvora: se trata de una vulnerabilidad bastante seria en SSL. Resumidamente, se trata de un clásico man-in-the-middle que podría explotar la renegociación de [...]</description>
		<content:encoded><![CDATA[<p>[...] cuenta: «Leo en Slashdot una noticia que se está extendiendo como la pólvora: se trata de una vulnerabilidad bastante seria en SSL. Resumidamente, se trata de un clásico man-in-the-middle que podría explotar la renegociación de [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous Coward</title>
		<link>http://www.links.org/?p=780&#038;cpage=1#comment-337001</link>
		<dc:creator>Anonymous Coward</dc:creator>
		<pubDate>Sat, 07 Nov 2009 05:42:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.links.org/?p=780#comment-337001</guid>
		<description>&gt; OpenSSL is written by monkeys

I think Linus specifically noted that the OpenBSD committers are a group of *masturbating* monkeys.

i.e., they care about security~</description>
		<content:encoded><![CDATA[<p>&gt; OpenSSL is written by monkeys</p>
<p>I think Linus specifically noted that the OpenBSD committers are a group of *masturbating* monkeys.</p>
<p>i.e., they care about security~</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David-Sarah Hopwood</title>
		<link>http://www.links.org/?p=780&#038;cpage=1#comment-336993</link>
		<dc:creator>David-Sarah Hopwood</dc:creator>
		<pubDate>Sat, 07 Nov 2009 04:02:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.links.org/?p=780#comment-336993</guid>
		<description>In response to comment 7:
CSRF is normally constrained to some extent by the same-origin policy; this isn&#039;t. In your example, the response to the img request can&#039;t be read by a script -- it can only be displayed (and if there were a way for an attacker to read the displayed pixels, that would be a browser bug).</description>
		<content:encoded><![CDATA[<p>In response to comment 7:<br />
CSRF is normally constrained to some extent by the same-origin policy; this isn&#8217;t. In your example, the response to the img request can&#8217;t be read by a script &#8212; it can only be displayed (and if there were a way for an attacker to read the displayed pixels, that would be a browser bug).</p>
]]></content:encoded>
	</item>
</channel>
</rss>
