Settings

Theme

Ticketbleed F5 bug undermines HTTPS

arstechnica.com

19 points by beaconfield 9 years ago · 6 comments

Reader

jsnfwlr 9 years ago

Thankfully this is limited to a single (and seemingly small) company's hardware, rather than the entire SSL/TLS stack. Glad it wasn't someone like Cisco too ...

  • synicalx 9 years ago

    I wouldn't say F5 is small, in fact for load balancing (or whatever the kids call that these days) they're over 50% of the market apparently - https://f5.com/about-us/news/twists/f5-gains-adc-market-shar...

  • bsagdiyev 9 years ago

    We had session tickets disabled already so weren't affected, but you'd be surprised some of the sites that use these devices. I believe AT&T has quite a number in use.

    • zonknz 9 years ago

      At one time Azure was built on a whole bunch of F5s. Unsure if they are still in the picture.

      • trome 9 years ago

        F5 is just across the water from Microsoft, and there is a lot of cross-pollination of employees between the two. Even if F5 wasn't the best choice, I wouldn't be surprised if they were used just due to familiarity.

  • meowface 9 years ago

    True, but F5 is still extremely popular with medium and large companies.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection