|
|
|
|
|
by tptacek
1464 days ago
|
|
Heartbleed isn't a TLS vulnerability any more than an overflow in GnuTLS is. The threshold question is, "could this vulnerability be reasonably expected to recur in independent implementations of the protocol?" As for stripping back TLS 1.1 --- it wouldn't take much more than simply picking a single ciphersuite and requiring TLS 1.1. You wouldn't need to know, for instance, about export ciphers. |
|