Holes discovered in SSL certificate validation
Holes discovered in SSL certificate validation
Posted Nov 2, 2012 14:22 UTC (Fri) by jezuch (subscriber, #52988)Parent article: Holes discovered in SSL certificate validation
> Given that there is some kind of security requirement for the application (why use SSL otherwise?)
I guess they had "encryption" on the requirements list, so they just slapped on some calls to some SSL library they googled and said "done!". And nobody cared about the requirement, really, it was just there to make the software look good in the eyes of managers and potential clients.
