|
|
|
|
|
by rckoepke
2243 days ago
|
|
> Traffic is encrypted using SSL/TLS libraries, but recall that all of the major SSL/TLS implementations have had highly publicized vulnerabilities. I'm not sure this is a valid criticism...wouldn't we be more worried if they were using anything else instead? |
|
Broken SSL => MITMer can possibly negotiate insecure and read your traffic anyway. MITMer can also possibly cause a denial-of-service, or get arbitrary code execution on that one chip that controls your entire CPU.
If I had to choose, I would take the first option.
(This precludes options like removing the IME entirely, or updating it to a version with non-broken SSL.)