An alleged SSL/TLS protocol vulnerability
Posted Sep 20, 2011 23:44 UTC (Tue) by
rickmoen (subscriber, #6943)
Parent article:
An alleged SSL/TLS protocol vulnerability
1. This is fundamentally just another XSS mode that permits a man in the middle bit of JavaScript to conduct a chosen-plaintext decryption of cookie data encrypted using an AES cipher-block-chained-(CBC-)mode block cipher. Therefore, the RequestPolicy Firefox extension is your friend, being a general preventative against XSS malarky.
2. You know that 'This page contains both secure and nonsecure items' warning you keep ignoring? Stop doing that.
3. As effective as RequestPolicy is, that plus NoScript is even better.
Rick Moen
rick@linuxmafia.com
(
Log in to post comments)