Slashdot Mirror


POODLE Flaw Returns, This Time Hitting TLS Protocol

angry tapir writes: If you patched your sites against a serious SSL flaw discovered in October you will have to check them again. Researchers have discovered that the POODLE vulnerability also affects implementations of the newer TLS protocol. The POODLE (Padding Oracle On Downgraded Legacy Encryption) vulnerability allows attackers who manage to intercept traffic between a user's browser and an HTTPS website to decrypt sensitive information, like the user's authentication cookies.

2 of 54 comments (clear)

  1. Re: A question I hope someone can answer by Anonymous Coward · · Score: 5, Insightful

    Have you considered upgrading your browser!

  2. Re:Test your site with this by Architect_sasyr · · Score: 3, Insightful

    The SSL Labs are a fantastic reference.

    Turns out when I was using their guides and aiming for an A+ rating in October (not long after I took over the current post) I accidentally mitigated TLS POODLE before it even became publicly known. So.. whoops? Better not follow the best practices guides next time, better just patch the vulnerabilities as they come ;)

    --
    Me failed English...
    FreeBSD over Linux. If my comments seem odd, this may explain...