* Posts by rybolov

1 publicly visible post • joined 21 Dec 2015

Security industry too busy improving security to do security right

rybolov

"migration from Secure Sockets Layer (SSL) to Transport Layer Security (SSL)."

Typo. Should be:

The Payment Card Industry Security Standards Council (PCI SSC) has decided to delay the deadline for migration from Secure Sockets Layer (SSL) to Transport Layer Security (TLS).

"SSL gave the world the Heartbleed, Shellshock and Poodle vulnerabilities."

Huh? Shellshock was a vulnerability in BASH. Had nothing to do with SSL or TLS. Heartbleed was a specific implementation inside OpenSSL, not the SSL or TLS protocols themselves. However, Poodle was a protocol vulnerability specific to SSL V3 with CBC ciphers so you're correct there. Just stop with the hyperbolic statements without fact-checking first because it makes you look like a ninny. Kthnx.