Settings

Theme

The POODLE bites again

imperialviolet.org

94 points by deepblueocean 11 years ago · 16 comments

Reader

tacoman 11 years ago

"This seems like a good moment to reiterate that everything less than TLS 1.2 with an AEAD cipher suite is cryptographically broken."

So this means AES-GCM essentially?

huxley 11 years ago

Link didn't work for me, here is the Google Cache text version:

http://webcache.googleusercontent.com/search?q=cache:f01MHrX...

resonantcore 11 years ago

We look forward to TLS 1.2 support being the norm. (And then, hopefully, the ratification and adoption of TLS 1.3)

A 50% adoption rate is excellent news. Still a long way to go, but that's worth toasting over.

  • yuhong 11 years ago

    What is frustrating is how many such servers have TLS 1.3 intolerance (even PayPal), and often the same servers are also affected by this bug. I wonder what TLS implementation is this.

cryptbe 11 years ago

POODLE worked not only against SSLv3, but also against any TLS implementations that check padding in SSLv3's style (e.g., just checking the last byte, and ignoring the rest of the padding). SSL accelerators from F5 and A10 were vulnerable. Thus, many of the world's largest sites were vulnerable.

eyeareque 11 years ago

Are there any more details than what this write up contains?

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection