Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's right and wrong.

It's wrong in that this is very much your problem. It's right in that there is nothing you can do about it except hope that all the people who might try to connect to your website are using a patched (or pre-broken) verison of OpenSSL.

Patching your server-side version of OpenSSL (while a good idea) will not solve the problem because certificate verification is done (as it must be) browser-side.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: