Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

From: Using Frankencerts for Automated Adversarial Testing of Certificate Validation in SSL/TLS Implementations

https://www.cs.utexas.edu/~shmat/shmat_oak14.pdf

github: https://github.com/sumanj/frankencert



The code used for the paper is actually here: https://github.com/pencilo/ssl

I quit gradschool a month after publishing this so can't comment on what Suman is currently working on, but it looks like it is still mostly my code for generation.

I didn't write the script for using polarSSL but I wrote most the other ones,the testing harness, cert generation and cert crawling, and I can say that polarSSL loved to crash on my weird certs. I almost wanted to remove them from the tested list for being so unreliable.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: