|
Five Ways to Screw Up SSL |
|
|
|
Source: Fr33d0m - Posted by Benjamin D. Thomas
|
SSL is a wonderful protocol, but it is frequently used
badly. This note is intended to point out some of the more
common errors made by applications using SSL.
This checklist should be useful for application developers,
system administrators, and the occasional penetration
tester. This note assumes you have at least a casual
knowledge of SSL, but is not a paper about cryptography. If
you know enough to write an SSL library, you will know
every single one of the mistakes I mention below, plus a
few more. Still, I hope that those of you who are writing
SSL toolkits will consider why these mistakes are made.
Perhaps it will help you design your toolkits so that
novices use them correctly.
Read this full article at Fr33d0m
Only registered users can write comments. Please login or register. Powered by AkoComment! |