«« Next » « Previous
Subversion
Written by: Lorna Jane Mitchell
Featured Refcardz: Top Refcardz:
  1. Git
  2. DNS
  3. Data Mining
  4. Spring Data
  5. Subversion
  1. Spring Data
  2. Subversion
  3. Spring Config.
  4. Spring Annotations
  5. Data Mining

Link Details

Link 868805 thumbnail
User 979839 avatar

By Mahoney266
via cs.utexas.edu
Published: Oct 26 2012 / 08:14

This paper alleges that many HTTPS clients, including Apache HttpClient 3.x and everything built on it (Axis 1 & 2, Apache CXF) either do not check the trust chain of a TSL certificate appropriately or do not validate that the certificate is for the domain they are trying to contact, in both cases opening themselves up to simple man-in-the-middle attacks. Whilst I have not validated its allegations I think they deserve to be taken seriously & particularly the advice that any application that is a client of a cloud based TLS secured service should actively test whether it allows connections to untrusted or wrong domain certificates.
  • 3
  • 0
  • 356
  • 562

Add your comment


Html tags not supported. Reply is editable for 5 minutes. Use [code lang="java|ruby|sql|css|xml"][/code] to post code snippets.

Voters For This Link (3)



Voters Against This Link (0)