19 ms·
there's currently no post on openssl.org but i expect them to publish one soon. Also, now with all the OpenSSL sh*tstorm this year, I really wonder if LibreSSL
by attilagyorffy 10y ago
there's currently no post on openssl.org but i expect them to publish one soon. Also, now with all the OpenSSL sh*tstorm this year, I really wonder if LibreSSL is vulnerable to this security problem...
- adrianN 10y agoLibreSSL has removed SSL3, so I'd guess it doesn't do "SSL3_AL_WARNING"
- cm3 10y agoAnd Firefox 52 is proposed to default to TLS 1.3 for safety and performance reasons: https://groups.google.com/forum/#!topic/mozilla.dev.platform/sfeqeMkyxCI https://groups.google.com/forum/#!topic/mozilla.dev.platform... I wish it was still possible to override these per profile. Last time I tried, the knobs were gone and had no effect whatsoever to enable safer defaults. I used to be able to force a minimum TLS version and enable only select few ciphers.
- detaro 10y agoSince in OpenSSL TLS is affected as well, I wouldn't be so sure.