4 ms·
SSLVerifySignedServerKeyExchange in http://opensource.apple.com/source/Security/Security-55471/libsecurity_ssl/lib/sslKeyExchange.c?txt http://opensource.apple.
by pencilo 13y ago
SSLVerifySignedServerKeyExchange in http://opensource.apple.com/source/Security/Security-55471/libsecurity_ssl/lib/sslKeyExchange.c?txt http://opensource.apple.com/source/Security/Security-55471/l...
If you want to see my favorite SSL bug ever.
- jey 13y agoOh god, that's horrifying. Get ready to check certificate validity, then report success before actually checking validity!
- deleted 13y ago[deleted]
- gojomo 13y agoWow. Maybe the inconsistent indentation and brackets-optional formatting helped the bug both arrive and persist? Perhaps a preferable practice for security-conscious code would be to only set a success value after all checks have passed, rather than trust intervening logic to reset a default-success value, to an error-value, before return.