Skip to content

Comment on The POODLE bites againparent

Comments

What is frustrating is how many such servers have TLS 1.3 intolerance (even PayPal), and often the same servers are also affected by this bug. I wonder what TLS implementation is this.

TLS 1.3 isn't finished yet...

I know, the goal is to prepare.

I'm not sure what you mean then by servers having TLS 1.3 intolerance.

It does not respond properly to clients trying to negotiate TLS 1.3. It should return a ServerHello showing the supported TLS 1.2 version.

I wasn't aware there was a TLS 1.3 PoC that people could use for testing.

It is as simple as setting the version in the ClientHello message.

Oh, I see

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.