 CaNsA Super Spammer

Joined: 02 Jan 2008 Karma :   
|
|
 stinkwheel Bovine Proctologist

Joined: 12 Jul 2004 Karma :    
|
 Posted: 17:50 - 24 Feb 2014 Post subject: |
 |
|
I'm going to take a wild stab in the dark here and suggest that apple have modified a piece of functional and well established open source software so that it only works with apple computers and in doing so have broken it. ____________________ “Rule one: Always stick around for one more drink. That's when things happen. That's when you find out everything you want to know.”
I did the 2010 Round Britain Rally on my 350 Bullet. 89 landmarks, 3 months, 9,500 miles. |
|
 Rogerborg nimbA

Joined: 26 Oct 2010 Karma :    
|
 Posted: 18:41 - 24 Feb 2014 Post subject: |
 |
|
An exploitable implementation of SSL does look more like enemy action than incompetence.
Did I say enemy? I meant friendly. Only The Terrorists rely on encryption. ____________________ Biking is 1/20th as dangerous as horse riding.
GONE: HN125-8, LF-250B, GPz 305, GPZ 500S, Burgman 400 // RIDING: F650GS (800 twin), Royal Enfield Bullet Electra 500 AVL, Ninja 250R because racebike |
|
 J.M. World Chat Champion

Joined: 27 Mar 2011 Karma :    
|
 Posted: 19:45 - 27 Feb 2014 Post subject: |
 |
|
https://gist.github.com/hongrich/9176925
Seems very deliberate. The issue is caused by line 62. It essentially ensures that the hash used during the key exchange always returns true, which makes a MITM attack possible. It must be noted that the attack has to be done during the SSL handshake, rather than during an active SSL session. ____________________ 2004 R1 & 2018 XSR900 |
|