Article 3RY8 Thought Komodia/Superfish Bug Was Really, Really Bad? It's Much, Much Worse!

Thought Komodia/Superfish Bug Was Really, Really Bad? It's Much, Much Worse!

by
from on (#3RY8)
Story ImageBut it gets worse. Filippo Valsorda has shown that you didn't even need to crack Komodia's weak password to launch a man-in-the-middle attack, but its SSL validation is broken, such that even if Komodia's proxy client sees an invalid certificate, it just makes it valid. Seriously.
External Content
Source RSS or Atom Feed
Feed Location http://lxer.com/module/newswire/headlines.rdf/
Feed Title
Feed Link http://lxer.com/
Reply 0 comments