Dan Kaminsky’s SSL Hell

posted Oct 30th 2006 3:08am by Eliot Phillips
filed under: Uncategorized


Here is another segment from Dan Kaminsky’s talk at Toorcon 8. You can download the high quality version here. He discovered approximately 1 in 3 deployed SSL boxes share a private key. This means that you can buy a box off of eBay and read encrypted SSL traffic from any identical box. He has also got a trick for making bank logins more secure.

Recent Posts



Reader Comments

Leave a Reply

hack a day serves up fresh hacks each day, every day from around the web and a special how-to hack each week.

send us your hacks





hacks

resources

rss newsfeeds

powered by wordpress

Most Commented On (30 days)

Recent Comments


  • Featured Mahalo How-Tos