3 ms·
This is exactly with what happened with Poodle and SSLv3 and it's in the article. Attackers were successfully downgrading to the vulnerable SSL when a TLS conne
by mkonecny 9y ago
This is exactly with what happened with Poodle and SSLv3 and it's in the article. Attackers were successfully downgrading to the vulnerable SSL when a TLS connection was attempted.
In the future when TLS1.2 is considered insecure, we do not want this workaround in place.