4 ms·
Additional security blogs regarding this vulnerability: http://hackersmag.blogspot.com/2011/09/beast-beating-ssl-tls-what-you-can-do.html http://hackersmag.blo
by rednaught 15y ago
Additional security blogs regarding this vulnerability:
http://hackersmag.blogspot.com/2011/09/beast-beating-ssl-tls-what-you-can-do.html http://hackersmag.blogspot.com/2011/09/beast-beating-ssl-tls...
http://www.phonefactor.com/blog/slaying-beast-mitigating-the-latest-ssltls-vulnerability.php http://www.phonefactor.com/blog/slaying-beast-mitigating-the...
http://www.schneier.com/blog/archives/2011/09/man-in-the-midd_4.html http://www.schneier.com/blog/archives/2011/09/man-in-the-mid...
Some comments: Appears RC4 is not FIPS approved if you need to do government work. Also, not all sites are RC4 compatible.
- marshray 15y agoThis one is from Eric Rescorla, a coauthor of many of the recent TLS RFCs: http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html http://www.educatedguesswork.org/2011/09/security_impact_of_...