oss-sec mailing list archives

Re: Truly scary SSL 3.0 vuln to be revealed soon:


From: Mark Felder <feld () feld me>
Date: Fri, 17 Oct 2014 15:33:47 -0500



On Fri, Oct 17, 2014, at 14:40, Daniel Kahn Gillmor wrote:

Nikos (or anyone else on OSS-security), are you sure that only browsers
do this?  what about mail clients like Thunderbird or Mail.app making
IMAPS or POPS or submission connections?


Arnt Gulbrandsen explains it pretty well here:

http://archives.aox.org/archives/mailstore-users/4847/thread


Current thread: