![]() |
|
|
#529 |
|
Undefined
"The unspeakable one"
Jun 2006
My evil lair
22·32·173 Posts |
|
|
|
|
|
|
#530 |
|
Bamboozled!
"𒉺𒌌𒇷𒆷đ’€"
May 2003
Down not across
2·5,393 Posts |
We're finding it difficult to scan so we'll destroy your legitimate business.
https://torrentfreak.com/under-u-s-p...-files-150227/ |
|
|
|
|
|
#531 | ||
|
"Gang aft agley"
Sep 2002
2·1,877 Posts |
Those old encryption export restrictions have left a massive security hole. We've be hearing more about this one.
Quote:
https://freakattack.com/ is a test for it. On my kindle fire tablet, https://freakattack.com/clienttest.html tells me: Quote:
|
||
|
|
|
|
|
#532 | |
|
Undefined
"The unspeakable one"
Jun 2006
My evil lair
22·32·173 Posts |
Quote:
Yet another reasons to stop the constant updating of features in browsers and start getting the bugs fixed.
|
|
|
|
|
|
|
#533 | |||
|
"Gang aft agley"
Sep 2002
2·1,877 Posts |
Quote:
Quote:
Quote:
|
|||
|
|
|
|
|
#534 | ||
|
"Gang aft agley"
Sep 2002
2·1,877 Posts |
Quote:
Quote:
|
||
|
|
|
|
|
#535 | |
|
∂2ω=0
Sep 2002
RepĂşblica de California
1164710 Posts |
Announcing the Surveillance Valley Project | Yasha Levine, Pando Daily
Quote:
|
|
|
|
|
|
|
#536 |
|
Tribal Bullet
Oct 2004
1101110101112 Posts |
Security downgrade attacks are a consequence of the choice of defaults in SSL libraries; more often than not they err on the side of letting users customize the library as much as they want but by default allowing as many SSL-enabled web sites to work as possible, as long as they handle the protocol correctly. The downside to this is that SSL libraries are very difficult to configure correctly.
Those defaults are also counterintuitive sometimes; if you are using OpenSSL manually, for example, the default behavior upon receiving a server certificate signed by an untrusted root is to allow the connection to go through but log an error. If you don't like that default you have a lot of code to write. In fact a paper published two years ago showed how a huge number of libraries and commercial frameworks that wrap an SSL library have no protection from man-in-the-middle attacks because you can literally give them a garbage certificate signed by anybody and the connection won't be refused. |
|
|
|
|
|
#537 | ||
|
"Gang aft agley"
Sep 2002
375410 Posts |
Today, Wikipedia and the ACLU are filing a lawsuit over NSA interception of and searching of text based traffic.
Stop Spying on Wikipedia Users NYTimes opinion page Quote:
Wikimedia v. NSA: Challenge to Mass Surveillance Under the FISA Amendments Act Quote:
Last fiddled with by only_human on 2015-03-10 at 17:28 Reason: added info from ACLU.org |
||
|
|
|
|
|
#538 | |
|
"Gang aft agley"
Sep 2002
2×1,877 Posts |
In other news:
iSpy: THE CIA CAMPAIGN TO STEAL APPLE’S SECRETS Quote:
|
|
|
|
|
|
|
#539 |
|
∂2ω=0
Sep 2002
RepĂşblica de California
19·613 Posts |
Latest nuggets from Kaspersky labs:
New smoking gun further ties NSA to omnipotent “Equation Group” hackers | Ars Technica |
|
|
|
![]() |
| Thread Tools | |
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| I'm rich AND on a government check. | jasong | jasong | 18 | 2013-08-12 18:21 |
| How does proper government manifest in regulation? | cheesehead | Soap Box | 10 | 2011-04-17 02:29 |