• Testing Your SSL Server for CRIME

    We still have to wait for later this week when Juliano Rizzo and Thai Duong will present their CRIME SSL/TLS attack at Ekoparty Security Conference. Regardless, we now know that the attack is based on the implementation of TLS compression or SPDY (pronounced “speedy”). CRIME uses the vulnerability that there is information leakage when data is compressed prior to encryption.

        in Secure Browsing, SSL, SSL Deployment
    0