Thread
Stories related to "On the (provable) security of TLS: Part 1" across the full archive.
A TLS library implemented with modern techniques to improve security. These include a memory-safe language, pure functions where possible, type-checking protocol steps, and a DSL for easier parsing. Result is library and runtime with 73-84% of bulk performance of unsafe OpenSSL with 25x less code in...
GnuTLS patches huge security hole that hung around for two years – worse than Heartbleed, says Google cryptoboffin
(theregister.com)
- https://nvd.nist.gov/vuln/detail/CVE-2020-13777
- https://github.com/0xxon/cve-2020-13777
An Empirical Study into the Security Exposure to Hosts of Hostile Virtualized Environments
(taviso.decsystem.org)