[Ach] POODLE on TLS < 1.2

Pepi Zawodsky pepi.zawodsky at maclemon.at
Tue Dec 9 13:52:14 CET 2014


On 09 Dec 2014, at 00:45, Aaron Zauner <azet at azet.org> wrote:
>> On 09 Dec 2014, at 00:20, Aaron Zauner <azet at azet.org> wrote:
>>> apply POODLE to TLS < 1.2.
> This only affects implementation that disregard proper padding checks in
> their TLS stack

Ok, so not TLS 1.1 or 1.2 protocol specification in particular but “only” implementations that do not follow said specification. As I expected. Thanks for confirming.



@Reed
No need to be sorry. Always good to see people help and care to answer!
Thanks!


SSL… the gift that keeps on giving! ;-)
Best regards
Pepi
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4130 bytes
Desc: not available
URL: <http://lists.cert.at/pipermail/ach/attachments/20141209/0ccf7300/attachment.bin>


More information about the Ach mailing list