LWN.net Logo

An alleged SSL/TLS protocol vulnerability

An alleged SSL/TLS protocol vulnerability

Posted Sep 21, 2011 6:52 UTC (Wed) by josh (subscriber, #17465)
In reply to: An alleged SSL/TLS protocol vulnerability by rickmoen
Parent article: An alleged SSL/TLS protocol vulnerability

Note that this attack does not require injecting JavaScript into the SSL site. The man-in-the-middle just has to inject JavaScript into any plain HTTP site open at the same time, and from there that JavaScript can poke at the SSL site in a way that helps the man-in-the-middle packet sniffer figure out how to decrypt your SSL session.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds