cryptlib and Poodle

Peter Gutmann <[email protected]> Fri, 17 Oct 2014 03:40:52 +1300
Newsgroups gmane.comp.encryption.cryptlib
Message-ID <[email protected]>
In order to pre-empt a pile of email about this, cryptlib isn't vulnerable.
The attack requires an implementation that will automatically negotiate back
to SSLv3 (which cryptlib won't, it defaults to TLS 1.1 for connections), that
performs operations under control of an attacker, typically via Javascript
(which cryptlib doesn't), and that uses certain types of authentication
objects passed over SSL like cookies (which cryptlib doesn't).  To put it more
directly, you really need to be a web browser to be vulnerable.

Peter.

_______________________________________________
Cryptlib mailing list
[email protected] via Mail: [email protected]
Archive: ftp://ftp.franken.de/pub/crypt/cryptlib/archives/
http://news.gmane.org/gmane.comp.encryption.cryptlib
Posts from non-subscribed addresses are blocked to prevent spam, please
subscribe in order to post messages.