3 ms·
We have some documentation on what we've done to learn from previous vulnerabilities: https://docs.rs/rustls/0.19.0/rustls/manual/index.html https://docs.rs/ru
by dochtman 6y ago
We have some documentation on what we've done to learn from previous vulnerabilities:
https://docs.rs/rustls/0.19.0/rustls/manual/index.html https://docs.rs/rustls/0.19.0/rustls/manual/index.html
We try very hard to model our code as a constrained state machine that closely follows the specification.
- astrange 6y agoThat looks good. For your amusement I remembered another state machine bug in an SSH implementation: https://nakedsecurity.sophos.com/2018/10/17/serious-ssh-bug-lets-crooks-log-in-just-by-asking-nicely/ https://nakedsecurity.sophos.com/2018/10/17/serious-ssh-bug-... It included some server states in the client state machine, so if a client sent the server its own "authentication successful" message it… just let them in.