Researchers Demo ASP.NET Crypto Attack
Trailrunner7 writes "The crypto attack against ASP.Net Web apps has gotten a lot of attention this week, and with good reason. Microsoft on Friday night issued a security advisory about the bug, warning customers that it poses a clear danger to their sites. Also on Friday, the researchers who found the bug and implemented the attack against it released a slick video demo of the attack, clearly showing the seriousness of the problem and how simple it is to exploit with their POET tool."
You need to keep in mind that most ASP.NET apps are developed in India. A fuck up like that is routine for them. In fact, I'd be much more surprised if they didn't screw up something as simple as that.
Standards are often riddled with security holes.