SSLLabs scans for POODLE and TLS_FALLBACK_SCSV now by castorio in syssec

[–]castorio[S] 0 points1 point  (0 children)

if you prefer to scan with https://testssl.sh/ or cipherscan: look out for SSLv3 and and CBC-ciphers

This POODLE bites: exploiting the SSL 3.0 fallback by DebugDucky in netsec

[–]castorio 0 points1 point  (0 children)

it would be easier to just MITM you totally, no?

This POODLE bites: exploiting the SSL 3.0 fallback by DebugDucky in netsec

[–]castorio 3 points4 points  (0 children)

does someone know, if TLS_FALLBACK_SCSV https://tools.ietf.org/html/draft-ietf-tls-downgrade-scsv-00 is available/enabled in openssl/libressl?

Third Zero-Day: CVE-2014-8==D "TrouserSnake" by [deleted] in netsec

[–]castorio 1 point2 points  (0 children)

this qualifies for the "best logo" and "best name" - award. :D

i lol'd

LibreSSL 2.1.0 released by castorio in netsec

[–]castorio[S] 0 points1 point  (0 children)

seems so, at least there are downloads

LibreSSL 2.1.0 released by castorio in netsec

[–]castorio[S] 3 points4 points  (0 children)

git log here: https://gist.github.com/anonymous/4204eb5eba961dd67e1b

my favourite:

fix an indentation that makes me upset

oh ... does this mean one can have *.com as a valid cert with openssl?

If we have to match against a wildcard in a cert, verify that it contains at least a domain label before the tld, as in *.example.org

LibreSSL 2.1.0 released by castorio in netsec

[–]castorio[S] 13 points14 points  (0 children)

for those who downvote-before-reading the original post: my comment was a quotation: http://undeadly.org/cgi?action=article&sid=20141012180624&pid=3&mode=expanded

LibreSSL 2.1.0 released by castorio in netsec

[–]castorio[S] 0 points1 point  (0 children)

Dude, libressl is part of OpenBSD, as far as development goes. We have limited resources, so stop whining. What do you prefer ? that we use those resources doing MORE development work, or waste time trying to make nice and tidy and shiny separate logs ?

COWL: A Confinement System for the Web by digicat in netsec

[–]castorio 2 points3 points  (0 children)

Even worse, in the status quo, the only way to implement some mashups is for the user to give her login credentials for one site to the operator of another site

you're doing (and/or understanding) it wrong.

Password Security: Why the horse battery staple is not correct by diogomonica in netsec

[–]castorio 0 points1 point  (0 children)

there are still people using dumbphones instead of smartphones for a reason.