Hacker News new | past | comments | ask | show | jobs | submit login

That would be a more compelling argument if any other TLS stack had ever had this particular validation bug in it. As it stands, the test case that you suppose should have existed is specific to exactly the code in GnuTLS, and applies to no other stack.



What is GnuTLS specific in "The failure may allow attackers using a self-signed certificate to pose as the cryptographically authenticated operator of a vulnerable website and to decrypt protected communications"? [1]

Apparently just a self signed cert. It was accepted as the "CA signed." Since 2005.

1) http://arstechnica.com/security/2014/03/critical-crypto-bug-...


No, that is not the bug.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: