<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>uncompiled.com &#187; SSL</title>
	<atom:link href="http://www.uncompiled.com/category/ssl/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.uncompiled.com</link>
	<description>Technology News That You Need</description>
	<lastBuildDate>Fri, 30 Jul 2010 01:19:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Researcher Reveals Major SSL and Browser Flaws</title>
		<link>http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/</link>
		<comments>http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/#comments</comments>
		<pubDate>Fri, 30 Jul 2010 01:14:14 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Conference]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1413</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>LAS VEGAS&#8211;A security researcher has found a slew of fundamental problems with the way that modern browsers are designed and built, leading to serious questions about the security of these applications and the way that they handle SSL sessions. </p>
<p>The research, done by Robert Hansen of SecTheory, shows that browsers such as Firefox, Internet Explorer and Chrome have a number of architectural problems that can essentially negate the security that SSL is meant to provide for sensitive Web transactions. The techniques that Hansen has developed, which he demonstrated at the Black Hat conference here Thursday, give an attacker the ability to do any number of nasty things to a target machine, including forcing the download of an executable file, overwriting the URL field in the browser and overwrite secure HTTPS cookies with non-secure cookies. </p>
<p>In all, Hansen found 24 problems before he decided to stop looking. &#8220;I had basically had to stop the research because there were just too many issues. I didn&#8217;t have time to deal with anymore,&#8221; Hansen said. </p>
<p>A big part of the problem, Hansen said in an interview, is that browsers don&#8217;t enforce policies that would isolate the tabs in an open browser from one another. This allows an attacker who can control one of the tabs, say a normal non-SSL session, to also affect content in the other tabs, even if they&#8217;re using SSL. Hansen identified several techniques that enable him to watch an SSL-protected session and glean a lot of information about what the user is doing, based on timing certain parts of the Web session and knowing how long it takes for part of a site to load. He also can tell whether a user is logged in on a given site and use a specific technique to log the user out so he can then watch the login operation and steal the credentials.</p>
<p>&#8220;When you look at it, what does SSL really offer? What this means is that for the average user, against a determined adversary, there really is no protection,&#8221; said Hansen, who presented his findings at the Black Hat conference here Thursday. &#8220;People give SSL and TLS a lot of credit, when it shouldn&#8217;t have any at all.&#8221;</p>
<p>SSL is the main transport security used by millions of Web sites to protect data being sent from browsers to Web servers. It&#8217;s been shown to be vulnerable to a number of different attacks, including several man-in-the-middle attacks, which could be used in conjunction with some of Hansen&#8217;s techniques to completely compromise a supposedly secure Web session.</p>
<p>&#8220;The most important thing is that if an attacker can map out the domain ahead of time, he can get a really good feel for how the site is built,&#8221; Hansen said. &#8220;If there&#8217;s a side channel, I can force them to precache some of the content on the page so that I don&#8217;t see that again when they reload the page. Then, the only thing you&#8217;re seeing are the things that are interesting to the attacker. You can map out the user&#8217;s flow around the site and the attacker can force the user to make an SSL connection to them so they can tell which SSL and HTTP headers are being sent in which direction. It&#8217;s about narrowing down the number of bytes that are interesting.&#8221;</p>
<p>As troubling as the problems that Hansen found are, he emphasized that they don&#8217;t mean that the sky is falling. </p>
<p>&#8220;You still need to be a man in the middle first and there are probably easier ways to attack people once you are, but there are a lot of issues here,&#8221; he said. &#8220;If there was better jitter and padding in SSL, a lof of this wouldn&#8217;t even be possible.&#8221;</p>
<p><a href="http://threatpost.com/en_us/blogs/researcher-reveals-major-ssl-and-browser-flaws-072910">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;n=Researcher+Reveals+Major+SSL+and+Browser+Flaws&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;title=Researcher+Reveals+Major+SSL+and+Browser+Flaws" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;t=Researcher+Reveals+Major+SSL+and+Browser+Flaws" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;title=Researcher+Reveals+Major+SSL+and+Browser+Flaws" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;title=Researcher+Reveals+Major+SSL+and+Browser+Flaws&amp;srcUrl=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;srcTitle=Researcher+Reveals+Major+SSL+and+Browser+Flaws&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;title=Researcher+Reveals+Major+SSL+and+Browser+Flaws&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Researcher%20Reveals%20Major%20SSL%20and%20Browser%20Flaws%22&amp;body=Link: http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;t=Researcher+Reveals+Major+SSL+and+Browser+Flaws" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;title=Researcher+Reveals+Major+SSL+and+Browser+Flaws&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;title=Researcher+Reveals+Major+SSL+and+Browser+Flaws" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;title=Researcher+Reveals+Major+SSL+and+Browser+Flaws" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Researcher+Reveals+Major+SSL+and+Browser+Flaws+-+http://b2l.me/admsaw&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;submitHeadline=Researcher+Reveals+Major+SSL+and+Browser+Flaws&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Researcher+Reveals+Major+SSL+and+Browser+Flaws&amp;body=Link: http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSL Certificates In Use Today Aren&#8217;t All Valid</title>
		<link>http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/</link>
		<comments>http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/#comments</comments>
		<pubDate>Tue, 29 Jun 2010 13:19:17 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1347</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>It should be no surprise that the SSL security certificate business is big business, considering how SSL certificates are seen as being on the frontlines of securing Web transactions against fraud. But new data suggests that SSL certificates are not all being configured correctly.</p>
<p>Security research firm Qualys is attempting to paint a detailed picture of SSL deployments and their shortcomings with a new, still under-development study that aims to deliver a deeper degree of information on the state of the SSL marketplace than what is currently known. Most industry intelligence on the subject thus far has come from Netcraft research reports and from vendor reports.</p>
<p>In its study, Qualys scanned 119 million domain names, but found that only 92 million were active. Approximately 12.4 million domains failed to resolve properly and 14.6 million failed to respond. Of the active domains that did respond, nearly 34 million responded to the Qualys scan on both port 80 and port 443. Port 80 is typically used for HTTP while port 443 is typically used for HTTPS-, SSL-secured Websites.</p>
<p>Digging a layer deeper into the active sites on Port 443, Ivan Ristic, director of engineering at Qualys, said in a Webcast that he found that only about 23 million of the sites were actually running SSL.</p>
<p>SSL certificates can be generated for any domain name. It is considered to be a best practice that the name on the SSL certificate matches the name of the domain on which the SSL certificate is being used, though Ristic&#8217;s research shows that&#8217;s not always the case.</p>
<p>&#8220;Only about 3.17 percent of the domain names matched,&#8221; Ristic said. &#8220;So we have about 22 million SSL servers with certificates that are completely invalid because they do not match the domain name on which they reside.&#8221;</p>
<p>Detecting invalid SSL certificates<br />
In a preview of a talk set to be delivered at this summer&#8217;s Black Hat USA conference, Ristic explained that his company has had an SSL security-checking service available publicly for some time. However, the Qualys SSL checker required that users came to the site to check their own SSL status. With the new research conducted by Ristic, Qualys set about scanning the Internet to collect information on how sites are implementing SSL.</p>
<p>&#8220;For us, the question is: How exactly is SSL used on the Internet as a whole?&#8221; Ristic said during the Webcast. &#8220;Interestingly enough, as popular as SSL is, no one had made public the information about how it is used.&#8221;</p>
<p>According to VeriSign, there are currently approximately 193 million domain names. In terms of SSL, Netcraft reports that there are 1.5 million SSL certificates. Ristic decided to focus his research on the total number of .com, .net, .org, .biz, .us and .info domains, which total 119 million domain names in total.</p>
<p>Ristic explained that he built a virtual machine that was able to run 2,000 threads in parallel to scan those millions of domain names. The process took him two days at a speed of 1,000 servers scanned per second.</p>
<p>In response to a question from InternetNews.com about his testing hardware and software infrastructure, Ristic noted that the scanning software had been custom-written for the task.</p>
<p>&#8220;The hardware was nothing special &#8212; I&#8217;m using a virtual server in the cloud and it&#8217;s just a medium-sized box,&#8221; Ristic said. &#8220;The trick to why the tests are quick is that it&#8217;s only a couple of network packets that are being exchanged, and that&#8217;s enough to determine if the server on the other side is capable of supporting the protocol.&#8221;</p>
<p>As part of the complete report that he is working on, Ristic said that he&#8217;ll be doing a deeper analysis of 720,000 SSL certificates that he uncovered in his initial scan and considers valid. The plan is to collect up to 300 data points on each SSL server to better understand how the certificates are deployed and configured.</p>
<p><a href="http://www.esecurityplanet.com/features/article.php/3890171/SSL-Certificates-In-Use-Today-Arent-All-Valid.htm">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;n=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;title=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;t=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;title=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;title=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid&amp;srcUrl=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;srcTitle=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;title=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22SSL%20Certificates%20In%20Use%20Today%20Aren%27t%20All%20Valid%22&amp;body=Link: http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;t=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;title=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;title=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;title=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid+-+http://b2l.me/7j2qh&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;submitHeadline=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid&amp;body=Link: http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SonicWall directors accept buyout offer</title>
		<link>http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/</link>
		<comments>http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/#comments</comments>
		<pubDate>Wed, 09 Jun 2010 13:41:09 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Financial]]></category>
		<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[VPN]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1295</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>SonicWall directors have accepted a US$717 million offer to sell the company to a group headed by Thoma Bravo, a private equity investment firm, with the aim of growing the company faster and developing products quicker than it could as a listed company.</p>
<p>The security appliance company is profitable and growing — its earnings last quarter were 17% higher than for the same quarter last year — but with the security appliances industry consolidating, it needs to grow faster, says Patrick Sweeney, vice president of product management for SonicWall. The company has $200 million in cash as well, he says.</p>
<p>If approved by shareholders, the deal will enable faster development of the company&#8217;s next big product push, called Super Massive, a jump to 10Gbit/s speeds for its unified threat management hardware with all the security features turned on, he says. &#8220;It&#8217;s important for us to grow as fast or faster than the market,&#8221; he says. &#8220;This will allow us to build a larger company a lot faster.&#8221;</p>
<p>Size is important because the industry is consolidating, he says, pointing to HP&#8217;s purchase of 3Com and its security devices division Tipping Point, making smaller companies more vulnerable.</p>
<p>As a listed company, SonicWall&#8217;s goals were constrained to ever increasing 90-day demands between fiscal reporting quarters, which limits longer term investments that can alter a company&#8217;s strategic course, he says.</p>
<p>SonicWall, which makes unified threat management, firewall, VPN and backup appliances as well as endpoint security, email security and antispam software, says the deal will buy out current shareholders for $11.50 per share in cash, which is 63 percent more than the stock is going for publicly. Stockholders still have to approve the deal, and that is expected by early in the fourth quarter of this year.</p>
<p><a href="http://computerworld.co.nz/news.nsf/security/sonicwall-directors-accept-buyout-offer">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/&amp;n=SonicWall+directors+accept+buyout+offer&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/&amp;title=SonicWall+directors+accept+buyout+offer" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/&amp;t=SonicWall+directors+accept+buyout+offer" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/&amp;title=SonicWall+directors+accept+buyout+offer" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/&amp;title=SonicWall+directors+accept+buyout+offer&amp;srcUrl=http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/&amp;srcTitle=SonicWall+directors+accept+buyout+offer&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/&amp;title=SonicWall+directors+accept+buyout+offer&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22SonicWall%20directors%20accept%20buyout%20offer%22&amp;body=Link: http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/&amp;t=SonicWall+directors+accept+buyout+offer" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/&amp;title=SonicWall+directors+accept+buyout+offer&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/&amp;title=SonicWall+directors+accept+buyout+offer" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/&amp;title=SonicWall+directors+accept+buyout+offer" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=SonicWall+directors+accept+buyout+offer+-+http://b2l.me/2d8bp&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/&amp;submitHeadline=SonicWall+directors+accept+buyout+offer&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=SonicWall+directors+accept+buyout+offer&amp;body=Link: http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/06/sonicwall-directors-accept-buyout-offer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenSSL updates fix vulnerabilities</title>
		<link>http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/</link>
		<comments>http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/#comments</comments>
		<pubDate>Thu, 03 Jun 2010 18:52:24 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Open-Source]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1271</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>The OpenSSL developers have released versions 0.9.8o and 1.0.0a, fixing two security problems. A flaw in the ASN.1 parser can be exploited to write to invalid memory addresses using specially crafted &#8220;Cryptographic Message Syntax&#8221; (CMS) structures. The flaw potentially allows arbitrary code to be injected in order to compromise a system. CMS is not enabled by default in the 0.9.8 branch of OpenSSL, but it is enabled in the 1.0.0 branch.</p>
<p>An uninitialised buffer in the EVP_PKEY_verify_recover() function in version 1.0.0 can be exploited to make an invalid RSA key appear to be valid. Since very few applications have used this recently-introduced function, the scope of this problem is limited. The OpenSSL developers say that pkeyutl is currently one of the only OpenSSL tools to access this function.</p>
<p><a href="http://www.h-online.com/security/news/item/OpenSSL-updates-fix-vulnerabilities-1014786.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;n=OpenSSL+updates+fix+vulnerabilities&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;title=OpenSSL+updates+fix+vulnerabilities" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;t=OpenSSL+updates+fix+vulnerabilities" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;title=OpenSSL+updates+fix+vulnerabilities" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;title=OpenSSL+updates+fix+vulnerabilities&amp;srcUrl=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;srcTitle=OpenSSL+updates+fix+vulnerabilities&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;title=OpenSSL+updates+fix+vulnerabilities&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22OpenSSL%20updates%20fix%20vulnerabilities%22&amp;body=Link: http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;t=OpenSSL+updates+fix+vulnerabilities" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;title=OpenSSL+updates+fix+vulnerabilities&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;title=OpenSSL+updates+fix+vulnerabilities" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;title=OpenSSL+updates+fix+vulnerabilities" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=OpenSSL+updates+fix+vulnerabilities+-+http://b2l.me/yxgcu&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;submitHeadline=OpenSSL+updates+fix+vulnerabilities&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=OpenSSL+updates+fix+vulnerabilities&amp;body=Link: http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gliffy, the popular online Visio replacement makes you pay for an SSL login</title>
		<link>http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/</link>
		<comments>http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 18:01:41 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Reviews]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1236</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p><strong>Update:</strong> So as you can see from the comment section, Chris Kohlhardt, the CEO of Gliffy took the time to reply and set the record straight from their end. Their login process is SSL-enabled for all, despite their statement of &#8220;Secure SSL login&#8221; only for Premium accounts is apparently an error in&#8230; semantics? It&#8217;s not really up to me to figure out whether the person who wrote that site copy is unaware of what the difference between a &#8216;secure SSL login&#8217; and &#8216;secure browsing&#8217; is, but I&#8217;d at least say to get that changed and not expect consumers to view an HTML source to find out the truth.</p>
<p>As I was logging into <a href="http://www.gliffy.com/">Gliffy</a> today for the first time in a few years, I noticed that there were two buttons to submit the login form with: one for a &#8216;basic&#8217; login and one for a &#8216;secure&#8217; login. To me, a secure login in 2010 <strong>is</strong> a basic login. The people behind Gliffy however believe that protecting your login credentials is worth at least $5/mo to you.<br />
<img src="http://www.uncompiled.com/wp-content/uploads/2010/06/Screen-shot-2010-06-02-at-1.56.28-PM.png" alt="" title="Gliffy Packages" width="500" height="310" class="alignright size-full wp-image-1262" /><br />
In a business model that offers both free and paid accounts, I feel that a company should make you pay for added features, storage, or accessibility to data that you are using their site for. I, like most people, realize that ad-based sites aren&#8217;t the preferred option. A site like Gliffy allows for many areas to make users pay for &#8216;more&#8217;. The number of documents you are able to store, file upload size limits, the number of users allowed to access your files. With all of these major points of wanting to upgrade, why nickel-and-dime our security?</p>
<p>It&#8217;s appreciated whenever a company offers free service, of any magnitude. What&#8217;s not appreciated, however, is when a company feels that they should charge you to securely give your username and a password to a form. The sharing of data networks is only continuing to grow and as-such, a vast majority of web sites (reputable ones, at least) at the very least encrypt your login credentials. Whether they encrypt all data during your session is a whole different matter, but most can agree that protecting credentials is a general necessity.</p>
<p>This isn&#8217;t meant to be a launch point for &#8216;well SSL is useless anyways&#8217;. SSL for credential logins is useful in the vast majority of situations people actually deal with every day. At this point in the Internet and networking, not allowing someone to choose to login securely with personal credentials for a reputable and fairly well-known (for the context) company, is ridiculous. </p>
<p>Lastly, I am not complaining that the Gliffy site doesn&#8217;t run in SSL for all content, merely that an SSL login should be provided, free of charge, to anyone using their service. This is a standard practice for most web sites and Gliffy should step-up and do the right thing for everyone&#8217;s privacy.</p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;n=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;title=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;t=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;title=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;title=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login&amp;srcUrl=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;srcTitle=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;title=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Gliffy%2C%20the%20popular%20online%20Visio%20replacement%20makes%20you%20pay%20for%20an%20SSL%20login%22&amp;body=Link: http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;t=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;title=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;title=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;title=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login+-+http://b2l.me/ynyvj&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;submitHeadline=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login&amp;body=Link: http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Mozilla removes inactive RSA root certificate</title>
		<link>http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/</link>
		<comments>http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 18:00:18 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Open-Source]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Mozilla has removed a deserted root certificate authority from its Firefox web browser after initially being unable to determine its current owner.</p>
<p>The root in question was added by RSA several years ago, but when Mozilla recently contacted the company &#8220;to confirm current contact and audit information&#8221; for the root, RSA was unable to offer details about the status of the root, Johnathan Nightingale, director of Firefox Development, said in a Tuesday blog post.</p>
<p>This prompted some worries among Mozilla developers, who said that VeriSign also could not take ownership of the root. Root certificates are critical parts of browsers, as they are used to sign, or validate, the authenticity of other certificates, such SSL connections used to secure website communications.</p>
<p>&#8220;We expect every root in our program to have a clear and active owner, and failing to get that clarity from RSA, we moved to pull this root from the product,&#8221; Nightingale said. &#8220;RSA has since confirmed that this root is no longer needed and can be removed from the product. That clarity, while late, is welcome and confirms our original decision&#8230;We regularly check for roots whose audits have lapsed or for whom we don&#8217;t have an up-to-date point of contact — it&#8217;s part of keeping our root program healthy.&#8221;</p>
<p>The root certificate, RSA Security 1024 V3, also appears in Apple&#8217;s root store. A spokesperson for the computing giant could not be reached for comment on Wednesday.</p>
<p><a href="http://www.scmagazineus.com/mozilla-removes-inactive-rsa-root-certificate/article/167537">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/&amp;n=Mozilla+removes+inactive+RSA+root+certificate&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/&amp;title=Mozilla+removes+inactive+RSA+root+certificate" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/&amp;t=Mozilla+removes+inactive+RSA+root+certificate" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/&amp;title=Mozilla+removes+inactive+RSA+root+certificate" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/&amp;title=Mozilla+removes+inactive+RSA+root+certificate&amp;srcUrl=http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/&amp;srcTitle=Mozilla+removes+inactive+RSA+root+certificate&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/&amp;title=Mozilla+removes+inactive+RSA+root+certificate&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Mozilla%20removes%20inactive%20RSA%20root%20certificate%22&amp;body=Link: http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/&amp;t=Mozilla+removes+inactive+RSA+root+certificate" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/&amp;title=Mozilla+removes+inactive+RSA+root+certificate&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/&amp;title=Mozilla+removes+inactive+RSA+root+certificate" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/&amp;title=Mozilla+removes+inactive+RSA+root+certificate" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Mozilla+removes+inactive+RSA+root+certificate+-+http://b2l.me/nnb9b&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/&amp;submitHeadline=Mozilla+removes+inactive+RSA+root+certificate&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Mozilla+removes+inactive+RSA+root+certificate&amp;body=Link: http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/04/mozilla-removes-inactive-rsa-root-certificate/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenSSL version 1.0.0 released</title>
		<link>http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/</link>
		<comments>http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 23:00:32 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Open-Source]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=960</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>OpenSSL &#8211; The Open Source toolkit for SSL/TLS</p>
<p>http://www.openssl.org/</p>
<p>   The OpenSSL project team is pleased to announce the release of<br />
   version 1.0.0 of our open source toolkit for SSL/TLS.  This new<br />
   OpenSSL version is a major release and incorporates many new<br />
   features as well as major fixes compared to 0.9.8n.  For a complete<br />
   list of changes, please see http://www.openssl.org/source/exp/CHANGES .</p>
<p>   The most significant changes are:</p>
<p>      o RFC3280 path validation: sufficient to process PKITS tests.<br />
      o Integrated support for PVK files and keyblobs.<br />
      o Change default private key format to PKCS#8.<br />
      o CMS support: able to process all examples in RFC4134<br />
      o Streaming ASN1 encode support for PKCS#7 and CMS.<br />
      o Multiple signer and signer add support for PKCS#7 and CMS.<br />
      o ASN1 printing support.<br />
      o Whirlpool hash algorithm added.<br />
      o RFC3161 time stamp support.<br />
      o New generalised public key API supporting ENGINE based algorithms.<br />
      o New generalised public key API utilities.<br />
      o New ENGINE supporting GOST algorithms.<br />
      o SSL/TLS GOST ciphersuite support.<br />
      o PKCS#7 and CMS GOST support.<br />
      o RFC4279 PSK ciphersuite support.<br />
      o Supported points format extension for ECC ciphersuites.<br />
      o ecdsa-with-SHA224/256/384/512 signature types.<br />
      o dsa-with-SHA224 and dsa-with-SHA256 signature types.<br />
      o Opaque PRF Input TLS extension support.<br />
      o Updated time routines to avoid OS limitations.</p>
<p>   We consider OpenSSL 1.0.0 to be the best version of OpenSSL available<br />
   and we strongly recommend that users of older versions upgrade as<br />
   soon as possible.  OpenSSL 1.0.0 is available for download via HTTP<br />
   and FTP from the following master locations (you can find the various<br />
   FTP mirrors under http://www.openssl.org/source/mirror.html):</p>
<p>     * http://www.openssl.org/source/<br />
     * ftp://ftp.openssl.org/source/</p>
<p>   The distribution file name is:</p>
<p>    o openssl-1.0.0.tar.gz<br />
      Size: 4010166<br />
      MD5 checksum: 89eaa86e25b2845f920ec00ae4c864ed<br />
      SHA1 checksum: 3f800ea9fa3da1c0f576d689be7dca3d55a4cb62</p>
<p>   The checksums were calculated using the following commands:</p>
<p>    openssl md5 openssl-1.0.0.tar.gz<br />
    openssl sha1 openssl-1.0.0.tar.gz</p>
<p>   Yours,</p>
<p>   The OpenSSL Project Team&#8230;</p>
<p>    Mark J. Cox             Nils Larsch         Ulf MÃƒÂ¶ller<br />
    Ralf S. Engelschall     Ben Laurie          Andy Polyakov<br />
    Dr. Stephen Henson      Richard Levitte     Geoff Thorpe<br />
    Lutz JÃƒÂ¤nicke            Bodo MÃƒÂ¶ller</p>
<p><a href="http://lwn.net/Articles/380949/">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/&amp;n=OpenSSL+version+1.0.0+released&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/&amp;title=OpenSSL+version+1.0.0+released" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/&amp;t=OpenSSL+version+1.0.0+released" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/&amp;title=OpenSSL+version+1.0.0+released" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/&amp;title=OpenSSL+version+1.0.0+released&amp;srcUrl=http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/&amp;srcTitle=OpenSSL+version+1.0.0+released&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/&amp;title=OpenSSL+version+1.0.0+released&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22OpenSSL%20version%201.0.0%20released%22&amp;body=Link: http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/&amp;t=OpenSSL+version+1.0.0+released" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/&amp;title=OpenSSL+version+1.0.0+released&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/&amp;title=OpenSSL+version+1.0.0+released" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/&amp;title=OpenSSL+version+1.0.0+released" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=OpenSSL+version+1.0.0+released+-+http://b2l.me/mm2sp&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/&amp;submitHeadline=OpenSSL+version+1.0.0+released&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=OpenSSL+version+1.0.0+released&amp;body=Link: http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/03/openssl-version-1-0-0-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Record of death&#8221; vulnerability in OpenSSL 0.9.8f through 0.9.8m</title>
		<link>http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/</link>
		<comments>http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 15:16:43 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Open-Source]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=950</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>In TLS connections, certain incorrectly formatted records can cause an OpenSSL<br />
client or server to crash due to a read attempt at NULL.</p>
<p>Affected versions depend on the C compiler used with OpenSSL:</p>
<p>- If &#8216;short&#8217; is a 16-bit integer, this issue applies only to OpenSSL 0.9.8m.<br />
- Otherwise, this issue applies to OpenSSL 0.9.8f through 0.9.8m.</p>
<p>Users of OpenSSL should update to the OpenSSL 0.9.8n release, which contains a<br />
patch to correct this issue.  If upgrading is not immediately possible, the<br />
source code patch provided in this advisory should be applied.</p>
<p>Bodo Moeller and Adam Langley (Google) have identified the vulnerability<br />
and prepared the fix.</p>
<p>Patch<br />
&#8212;&#8211;</p>
<p>&#8212; ssl/s3_pkt.c	24 Jan 2010 13:52:38 -0000	1.57.2.9<br />
+++ ssl/s3_pkt.c	24 Mar 2010 00:00:00 -0000<br />
@@ -291,9 +291,9 @@<br />
 			if (version != s->version)<br />
 				{<br />
 				SSLerr(SSL_F_SSL3_GET_RECORD,SSL_R_WRONG_VERSION_NUMBER);<br />
-				/* Send back error using their<br />
-				 * version number :-) */<br />
-				s->version=version;<br />
+                                if ((s->version &#038; 0xFF00) == (version &#038; 0xFF00))<br />
+                                	/* Send back error using their minor version number :-) */<br />
+					s->version = (unsigned short)version;<br />
 				al=SSL_AD_PROTOCOL_VERSION;<br />
 				goto f_err;<br />
 				}</p>
<p>This vulnerability is tracked as CVE-2010-0740.</p>
<p><a href="http://openssl.org/news/secadv_20100324.txt">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/&amp;n=%22Record+of+death%22+vulnerability+in+OpenSSL+0.9.8f+through+0.9.8m&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/&amp;title=%22Record+of+death%22+vulnerability+in+OpenSSL+0.9.8f+through+0.9.8m" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/&amp;t=%22Record+of+death%22+vulnerability+in+OpenSSL+0.9.8f+through+0.9.8m" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/&amp;title=%22Record+of+death%22+vulnerability+in+OpenSSL+0.9.8f+through+0.9.8m" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/&amp;title=%22Record+of+death%22+vulnerability+in+OpenSSL+0.9.8f+through+0.9.8m&amp;srcUrl=http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/&amp;srcTitle=%22Record+of+death%22+vulnerability+in+OpenSSL+0.9.8f+through+0.9.8m&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/&amp;title=%22Record+of+death%22+vulnerability+in+OpenSSL+0.9.8f+through+0.9.8m&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22%22Record%20of%20death%22%20vulnerability%20in%20OpenSSL%200.9.8f%20through%200.9.8m%22&amp;body=Link: http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/&amp;t=%22Record+of+death%22+vulnerability+in+OpenSSL+0.9.8f+through+0.9.8m" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/&amp;title=%22Record+of+death%22+vulnerability+in+OpenSSL+0.9.8f+through+0.9.8m&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/&amp;title=%22Record+of+death%22+vulnerability+in+OpenSSL+0.9.8f+through+0.9.8m" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/&amp;title=%22Record+of+death%22+vulnerability+in+OpenSSL+0.9.8f+through+0.9.8m" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=%22Record+of+death%22+vulnerability+in+OpenSSL+0.9.8f+through+0.9.8m+-+http://b2l.me/mkx9m&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/&amp;submitHeadline=%22Record+of+death%22+vulnerability+in+OpenSSL+0.9.8f+through+0.9.8m&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=%22Record+of+death%22+vulnerability+in+OpenSSL+0.9.8f+through+0.9.8m&amp;body=Link: http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/03/record-of-death-vulnerability-in-openssl-0-9-8f-through-0-9-8m/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8216;Severe&#8217; OpenSSL vuln busts public key crypto</title>
		<link>http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/</link>
		<comments>http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/#comments</comments>
		<pubDate>Fri, 05 Mar 2010 00:33:41 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Open-Source]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=849</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Computer scientists say they&#8217;ve discovered a &#8220;severe vulnerability&#8221; in the world&#8217;s most widely used software encryption package that allows them to retrieve a machine&#8217;s secret cryptographic key.</p>
<p>The bug in the OpenSSL cryptographic library is significant because the open-source package is used to protect sensitive data in countless applications and operating systems throughout the world. Although the attack technique is difficult to carry out, it could eventually be applied to a wide variety of devices, particularly media players and smartphones with anti-copying mechanisms.</p>
<p>&#8220;Wherever you need to verify the origin of a piece of software or a piece of information, those building blocks come in handy,&#8221; said Karsten Nohl, an independent security researcher who in unrelated attacks has broken encryption in widely used smartcards  and cordless phones. &#8220;The OpenSSL library provides much more than just SSL.&#8221;</p>
<p>The scientists, from the University of Michigan&#8217;s electrical engineering and computer science departments, said the bug is easily fixed by applying cryptographic &#8220;salt&#8221; to an underlying error-checking algorithm. The additional randomization would make the attack unfeasible.</p>
<p>An OpenSSL official, who asked that his name not be published, said engineers are in the process of pushing out a patch and stressed the attack is difficult to carry out in real-world settings.</p>
<p>The university scientists found that they could deduce tiny pieces of a private key by injecting slight fluctuations in a device&#8217;s power supply as it was processing encrypted messages. In a little more than 100 hours, they were able to feed the device enough &#8220;transient faults&#8221; that they were able to assemble the entirety of its 1024-bit key.</p>
<p>&#8220;This is probably not as much of a threat to a server system as it is to a consumer device,&#8221; said Todd Austin, one of the scientists who devised the attack. &#8220;The place where this would be more applicable would be if you want to attack a Blu-ray player (where) you have an environment where someone is giving you a device that has a private key to protect intellectual property and you have physical access to the device.&#8221;</p>
<p>Servers, by contrast, would be much harder to attack because they are generally located in places that prevent people from manipulating their power supply. But that doesn&#8217;t mean they&#8217;re immune to such exploits. In events where a machine was overheating or otherwise experiencing power fluctuations, the vulnerability will cause servers to leak secret data that could be intercepted by attackers.</p>
<p>The scientists are also experimenting with the possibility of exploiting the bug using lasers or natural radiation sources, they said.</p>
<p>The attack is enabled by what the researchers described as a &#8220;severe vulnerability&#8221; in the OpenSSL innards that carry out authentication based on the RSA public key encryption algorithm. It resides in the so-called fixed window exponentiation algorithm of the open-source crypto library, which is used when errors arise. By triggering a single-bit error in a multiplication operation, the scientists were able to force OpenSSL to divulge 4 bits of the secret key.</p>
<p>Once they gathered about 8,800 malformed messages from the targeted device, they fed the data into an 81-machine cluster of 2.4 GHz Pentium-4 systems running a custom-designed algorithm. They applied the technique to an embedded hardware device consisting of a Sparc processor running a Linux operating system and were able to extract its 1024-bit private key in 104 hours.</p>
<p>The researchers said it may be possible to apply the method to other crypto libraries, such as one offered by the Mozilla Foundation.</p>
<p><a href="http://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability/">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/&amp;n=%27Severe%27+OpenSSL+vuln+busts+public+key+crypto&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/&amp;title=%27Severe%27+OpenSSL+vuln+busts+public+key+crypto" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/&amp;t=%27Severe%27+OpenSSL+vuln+busts+public+key+crypto" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/&amp;title=%27Severe%27+OpenSSL+vuln+busts+public+key+crypto" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/&amp;title=%27Severe%27+OpenSSL+vuln+busts+public+key+crypto&amp;srcUrl=http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/&amp;srcTitle=%27Severe%27+OpenSSL+vuln+busts+public+key+crypto&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/&amp;title=%27Severe%27+OpenSSL+vuln+busts+public+key+crypto&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22%27Severe%27%20OpenSSL%20vuln%20busts%20public%20key%20crypto%22&amp;body=Link: http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/&amp;t=%27Severe%27+OpenSSL+vuln+busts+public+key+crypto" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/&amp;title=%27Severe%27+OpenSSL+vuln+busts+public+key+crypto&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/&amp;title=%27Severe%27+OpenSSL+vuln+busts+public+key+crypto" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/&amp;title=%27Severe%27+OpenSSL+vuln+busts+public+key+crypto" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=%27Severe%27+OpenSSL+vuln+busts+public+key+crypto+-+http://b2l.me/h35hp&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/&amp;submitHeadline=%27Severe%27+OpenSSL+vuln+busts+public+key+crypto&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=%27Severe%27+OpenSSL+vuln+busts+public+key+crypto&amp;body=Link: http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/03/severe-openssl-vuln-busts-public-key-crypto/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Harden TLS/SSL &#8211; Tool release</title>
		<link>http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/</link>
		<comments>http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 17:21:25 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[SSL]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=760</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>============================================<br />
TOOL: Harden SSL/TLS beta<br />
OS: Windows (2000,XP,Seven,2003,2008,2008R2)<br />
Requirement : .NET Framework 2.0<br />
Author : Thierry Zoller for G-SEC Ltd.<br />
============================================</p>
<p>Developed as part of G-SEC&#8217;s investigation into the<br />
&#8220;Secure SSL/TLS configuration Report 2010&#8243; (to be<br />
published) we developed this little tool.</p>
<p>&#8220;Harden SSL/TLS&#8221; hardens the default SSL/TLS settings of<br />
Windows 2000,2003,2008,2008R2, XP,Vista,7. It allows to<br />
remotely set SSL/TLS policies allowing or denying certain<br />
ciphers/hashes or complete ciphersuites.</p>
<p>It took longer then I expected to create this tool, Windows<br />
7 really strengthened the cryptosuites and introduced a new<br />
way Windows handles SCHANNEL policies and required quite<br />
some re-engineering. For instance, I had to create a mini<br />
state engine just for the preferred cipher list.</p>
<p>Harden SSL/TLS allows setting policies with regards<br />
to what ciphers and protocols are available to applications<br />
that use SCHANNEL crypto interface. A lot of windows<br />
applications do use this interface, for instance IIS, Google<br />
Chrome as well as Apple Safari and many more.</p>
<p>By changing the settings you can indirectly control<br />
what ciphers and protocols these applications are<br />
allowed to use and stay compliant to whatever policies<br />
you use.</p>
<p>Note: unfortunately neither chrome nor safari make use<br />
of the new TLS 1.2 protocol that Windows 7 introduced<br />
(hint hint). They both use SCHANNEL and just need to<br />
add a parameter to the SCHANNEL initialization in<br />
order to support it. (Let&#8217;s see who is first)</p>
<p>It allows to allow or deny:<br />
·  Hashes<br />
·  Keyexchange algorithms<br />
·  Protocols<br />
·  Ciphers &#038; Ciphersuites<br />
·  Priority of preferred Ciphersuites</p>
<p>Advanced mode<br />
· Re-enable ECC P521 mode on Windows7 and 2008R2<br />
  (P521 mode was available on Vista and 2008 but removed in<br />
  Windows7 and 2008R2)<br />
· Enable TLS 1.2 support on IIS 7.5 (off by default)<br />
· Set TLS Cache size and timeout</p>
<p>Download and Information:</p>
<p>http://blog.g-sec.lu/2010/02/harden-ssltls-tool-release.html</p>
<p>Documentation :</p>
<p>http://www.g-sec.lu/sslharden/documentation.pdf</p>
<p>Video :</p>
<p>http://www.g-sec.lu/sslharden/harde_ssl.swf</p>
<p>&#8211; </p>
<p>http://www.g-sec.lu</p>
<p>Thierry Zoller</p>
<p><a href="http://seclists.org/fulldisclosure/2010/Feb/322">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/&amp;n=Harden+TLS%2FSSL+-+Tool+release&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/&amp;title=Harden+TLS%2FSSL+-+Tool+release" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/&amp;t=Harden+TLS%2FSSL+-+Tool+release" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/&amp;title=Harden+TLS%2FSSL+-+Tool+release" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/&amp;title=Harden+TLS%2FSSL+-+Tool+release&amp;srcUrl=http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/&amp;srcTitle=Harden+TLS%2FSSL+-+Tool+release&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/&amp;title=Harden+TLS%2FSSL+-+Tool+release&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Harden%20TLS%2FSSL%20-%20Tool%20release%22&amp;body=Link: http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/&amp;t=Harden+TLS%2FSSL+-+Tool+release" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/&amp;title=Harden+TLS%2FSSL+-+Tool+release&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/&amp;title=Harden+TLS%2FSSL+-+Tool+release" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/&amp;title=Harden+TLS%2FSSL+-+Tool+release" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Harden+TLS%2FSSL+-+Tool+release+-+http://b2l.me/gmp8w&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/&amp;submitHeadline=Harden+TLS%2FSSL+-+Tool+release&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Harden+TLS%2FSSL+-+Tool+release&amp;body=Link: http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/02/harden-tlsssl-tool-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
