For the nth time in the last couple of years, security experts are warning about a new Internet-scale vulnerability, this time in some popular SSL clients. The flaw allows an attacker to force clients to downgrade to weakened ciphers and break their supposedly encrypted communications through a man-in-the-middle attack.
Researchers recently discovered that some SSL clients, including OpenSSL, will accept weak RSA keys
The link for this article located at Wired is no longer available.
We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.