<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SSL on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/ssl/</link>
    <description>Recent content in SSL on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 29 Apr 2015 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/ssl/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SSL Tidbits at the BASTA.NET</title>
      <link>https://insinuator.net/2015/04/ssl-tidbits-at-the-basta.net/</link>
      <pubDate>Wed, 29 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/ssl-tidbits-at-the-basta.net/</guid>
      <description>&lt;p&gt;A while a go Dominik and I gave an introductory presentation about SSL at the BASTA.NET conference, a developer-oriented event held in Darmstadt twice a year. At that time there were quite some enthusiastic participants but recently we’ve also gotten some inquiries asking for the relevant materials. Although there’s no recording of the session, we’ve decided to put the slides here for those interested who didn’t make it to the talk.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New SSL/TLS MiTM Attacks</title>
      <link>https://insinuator.net/2009/11/new-ssl/tls-mitm-attacks/</link>
      <pubDate>Mon, 09 Nov 2009 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2009/11/new-ssl/tls-mitm-attacks/</guid>
      <description>&lt;p&gt;A number of customers has approached us with questions like “Those new MiTM attacks against SSL/TLS, what’s their impact as for the security of our SSL VPNs with client certificates”?&lt;br&gt;&#xA;In the following we give our estimation, based on the information publicly available as of today.&lt;/p&gt;&#xA;&lt;p&gt;On 11/04/09 two security researchers (Marsh Ray and Steve Dispensa) published a &lt;a href=&#34;http://extendedsubset.com/Renegotiating_TLS.pdf&#34;&gt;paper&lt;/a&gt; describing some previously (presumably/hopefully) unknown MiTM attacks against SSL/TLS. CVE-2009-3555 was assigned to the underlying vulnerabilities within SSL/TLS.&lt;br&gt;&#xA;The attacks described might potentially allow an attacker to hijack an authenticated user’s (SSL/TLS) session. In an &lt;a href=&#34;https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt&#34;&gt;IETF draft&lt;/a&gt; published 11/09/09 and describing a potential protocol extension intended to mitigate the attacks the following is stated:&lt;br&gt;&#xA;“SSL and TLS renegotiation are vulnerable to an attack in which the attacker forms a TLS connection with the target server, injects content of his choice, and then splices in a new TLS connection from a client.  The server treats the client’s initial TLS handshake as a renegotiation and thus believes that the initial data transmitted by the attacker is from the same entity as the subsequent client data.”&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
