diff options
author | cinap_lenrek <cinap_lenrek@felloff.net> | 2016-04-22 02:33:29 +0200 |
---|---|---|
committer | cinap_lenrek <cinap_lenrek@felloff.net> | 2016-04-22 02:33:29 +0200 |
commit | 17a67eeb652ebc76f6fc9f7f7bbed501187d24e1 (patch) | |
tree | 0f16b638f4aafbe7009354c1ebd689419f85bb19 /sys/src/cmd/auth | |
parent | 7b3334775edcfe43fc6ff44955b09dc294d96974 (diff) |
libsec: implement server side SCSV preventing silly client fallbacks
silly clients (web*) reconnect when the handshake failed with a lower
protocol version, which allows downgrade attacks (POODLE). but instead
of stopping this madness, they invented a new magic TLSID to indicate
to the server that this connection attempt is a retry, and rely on the
server to notice and stop them from sabotaging themselfs.
Diffstat (limited to 'sys/src/cmd/auth')
0 files changed, 0 insertions, 0 deletions