Welcome! Log In Create A New Profile

Advanced

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Gena Makhomed
October 19, 2014 12:56PM
On 17.10.2014 16:24, Maxim Dounin wrote:

>> Кроме самых новых версий Firefox/Chrome на руках и пользователей
>> остается ведь очень много и других, более старых версий браузеров.
>> Которые умеют TLSv1 и которым для нормальной работы не нужен SSLv3.
>
> Браузер, который не обновляют - это браузер, рассматривать который
> с точки зрения безопасности достаточно бессмысленно, он всё равно
> дыряв, так или иначе. И хорошо, если в качестве дырки будет
> выступать POODLE, а не remote code execution.
>
> С точки зрения безопасности имеет смысл рассматривать только
> актуальные версии современных браузеров. И тут уже, судя по
> всему, проблема решена как минимум в Chrome и Opera[1], и скоро
> будет решена в Firefox. Ждём Safari и IE.
>
> [1] http://blogs.opera.com/security/2014/10/security-changes-opera-25-poodle-attacks/
>

Почему оставление включенным по умолчанию уязвимого протокола SSLv3
выглядит более предпочитетельным вариантом, если "с точки зрения
безопасности" старых версий браузеров как бы и не существует?

Буква 'S' в аббревиатурах "HTTPS" и "SSL" обозначает слово "Secure".

Разве не лучше сделать сброс подключения по протоколу SSLv3 вместо
того, чтобы делать вид, что обмен данными между клиентом и сервером
надежно зашифрован и скрыт от посторонних глаз. Ведь там могут быть,
например, данные кредитных карт или другая sensitive information,
которая крайне не желательна к попаданию в руки man-in-the-middle.

--
Best regards,
Gena

_______________________________________________
nginx-ru mailing list
nginx-ru@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx-ru
Subject Author Posted

CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Gena Makhomed October 15, 2014 09:06AM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Maxim Dounin October 15, 2014 09:34AM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Gena Makhomed October 15, 2014 12:08PM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Maxim Dounin October 15, 2014 01:42PM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Илья Шипицин October 16, 2014 12:08AM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

mente October 16, 2014 04:16AM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Maxim Dounin October 16, 2014 09:46AM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Gena Makhomed October 16, 2014 03:50PM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Gena Makhomed October 16, 2014 03:18PM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Maxim Dounin October 16, 2014 04:38PM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Gena Makhomed October 17, 2014 07:36AM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Maxim Dounin October 17, 2014 09:26AM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Gena Makhomed October 19, 2014 12:56PM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Maxim Dounin October 20, 2014 12:16AM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

mva October 20, 2014 01:28AM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Илья Шипицин October 20, 2014 04:40AM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Илья Шипицин October 16, 2014 12:06AM

Re[2]: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Михаил Монашёв October 16, 2014 04:06AM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Илья Шипицин October 20, 2014 04:48AM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Aleksandr Sytar October 16, 2014 07:36AM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

igor.goncharenko October 17, 2014 03:37AM

Re: CVE-2014-3566, important SSLv3 vulnerability, known as Poodle.

Maxim Dounin October 17, 2014 09:26AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 308
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready