Wednesday, October 15, 2014

OpenSSL: SSLv3 POODLE Vulnerability Official Release

So much for SSL v3.  Make sure your browser supports TLS.  For those of you still on IE 6/7 remember there are tribes in the Amazon who've never had contact with the outside world running higher versions of IE.

From SANS ISC:

OpenSSL: SSLv3 POODLE Vulnerability Official Release

"SSLv3 had issues in the past. Remember the BEAST attack? It was never resolved (other then moving to TLS 1.1/2). The only alternative was to use a stream cipher like RC4, which had its own problems."

No comments:

Post a Comment