🦞🌯 Lobster Roll

Thread

Kazakhistan to MITM all SSL traffic (telecom.kz)

Stories related to "Kazakhistan to MITM all SSL traffic" across the full archive.

Kazakhistan to MITM all SSL traffic (telecom.kz)
Research team finds flaws in SSL APIs, including libcurl, allowing MITM attacks (cs.utexas.edu)
DetecTor: client side SSL/TLS MITM detection through Tor (detector.io)
I threw together a Golang MITMing proxy to demonstrate Apple's SSL flaw (github.com)
New Lenovo laptops bundled with MITM cert/proxy to insert ads on SSL traffic (thenextweb.com)
"Smart" fridge doesn't validate SSL, vulnerable to MITM (digitaljournal.com)
Debugging SSL in Java using mitmproxy (blog.packagecloud.io)
Is there a case for a unified SSL front? (daniel.haxx.se)
SSLShader - GPU-accelerated SSL Proxy (shader.kaist.edu)
New Burp Proxy cracks Android SSL (h-online.com)
AnonymousClassLoader Java Exploitation Technique (immunityproducts.blogspot.com)
SSL certificate validation and DNSSEC (jpmens.net)
Enhancing digital certificate security (fake *.google.com SSL cert issued) (googleonlinesecurity.blogspot.de)
OpenBSD relayd SSL interception (marc.info)
Any Firefox add-on people out there? [Plugin for validating SSL via DNS] (blather.michaelwlucas.com)
The ICSI SSL Notary: CA Certificates (notary.icsi.berkeley.edu)
SSL And the Future Of Authenticity (2011) (thoughtcrime.org)
CloudFlare, PRISM, and Securing SSL Ciphers (blog.cloudflare.com)
SSL: Intercepted today, decrypted tomorrow (news.netcraft.com)
BREACH: SSL, Gone in 30 Seconds (breachattack.com)
Web Security Relies on SSL Which Relies on Email Which is Broken (blog.whitehatsec.com)
Lavabit SSL Certificate has been revoked (lavabit.com)
Why Android SSL was downgraded from AES256-SHA to RC4-MD5 in late 2010 (op-co.de)
Easier understanding of the Debian OpenSSL bug (tedunangst.com)
Namecoin, A Replacement For SSL (blog.mediocregopher.com)
How does the NSA break SSL? (blog.cryptographyengineering.com)
Weak Password Used to Access Hypervisor, Deface OpenSSL Site (threatpost.com)
There was some speculation that a compromise of the hypervisor code itself was the way the OpenSSL site was defaced, but it now appears to just be a weak password.
Improving GitHub's SSL setup (github.com)
How's My SSL (howsmyssl.com)
Beyond SSL client cert authentication: authorization (spootnik.org)