<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Authentication Gap in TLS Renegotiation</title>
	<atom:link href="http://extendedsubset.com/?feed=rss2&#038;p=8" rel="self" type="application/rss+xml" />
	<link>http://extendedsubset.com/?p=8</link>
	<description>"X is the new Y" is the new "Z considered harmful"</description>
	<pubDate>Tue, 07 Sep 2010 03:48:24 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: SSL Renegotiation Vulnerability :Architecting Security</title>
		<link>http://extendedsubset.com/?p=8#comment-316</link>
		<dc:creator>SSL Renegotiation Vulnerability :Architecting Security</dc:creator>
		<pubDate>Sun, 23 May 2010 19:41:11 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=8#comment-316</guid>
		<description>[...] at 9:41 pm     In November 2009, the renegotiation vulnerability over SSL/TLS based protocols was published.  SSL renegotiation is a new SSL handshake over an already established SSL [...]</description>
		<content:encoded><![CDATA[<p>[...] at 9:41 pm     In November 2009, the renegotiation vulnerability over SSL/TLS based protocols was published.  SSL renegotiation is a new SSL handshake over an already established SSL [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Digital Threat &#187; Blog Archive &#187; SSL/TSL Protocol Vulnerability</title>
		<link>http://extendedsubset.com/?p=8#comment-262</link>
		<dc:creator>Digital Threat &#187; Blog Archive &#187; SSL/TSL Protocol Vulnerability</dc:creator>
		<pubDate>Sat, 27 Feb 2010 22:47:51 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=8#comment-262</guid>
		<description>[...] Extended Subset and Links carry extensive technical descriptions of various application protocol issues resulting from this TLS vulnerability. [...]</description>
		<content:encoded><![CDATA[<p>[...] Extended Subset and Links carry extensive technical descriptions of various application protocol issues resulting from this TLS vulnerability. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: daniel.haxx.se &#187; The big protocols</title>
		<link>http://extendedsubset.com/?p=8#comment-252</link>
		<dc:creator>daniel.haxx.se &#187; The big protocols</dc:creator>
		<pubDate>Sun, 24 Jan 2010 21:53:59 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=8#comment-252</guid>
		<description>[...] the flaws discovered during the last year or so, primarily the the null-prefix cert names and the TLS renegotiation bug. I felt good about already knowing just about everything of what he told us. I can also boast with [...]</description>
		<content:encoded><![CDATA[<p>[...] the flaws discovered during the last year or so, primarily the the null-prefix cert names and the TLS renegotiation bug. I felt good about already knowing just about everything of what he told us. I can also boast with [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SSLv3 / TLS Man in the Middle vulnerability - Madrock</title>
		<link>http://extendedsubset.com/?p=8#comment-247</link>
		<dc:creator>SSLv3 / TLS Man in the Middle vulnerability - Madrock</dc:creator>
		<pubDate>Wed, 20 Jan 2010 02:17:22 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=8#comment-247</guid>
		<description>[...] The original description (site is suffering from a slashdot effect as I write this) [...]</description>
		<content:encoded><![CDATA[<p>[...] The original description (site is suffering from a slashdot effect as I write this) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MitM Plaintext Injection Vulnerability in TLS (openssl) &#171; waffle</title>
		<link>http://extendedsubset.com/?p=8#comment-34</link>
		<dc:creator>MitM Plaintext Injection Vulnerability in TLS (openssl) &#171; waffle</dc:creator>
		<pubDate>Sun, 13 Dec 2009 12:26:51 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=8#comment-34</guid>
		<description>[...] vulnerability and mitigation&#8217; &#8211; MARC Links » Another Protocol Bites The Dust Extended Subset » Blog Archive » Authentication Gap in TLS Renegotiation The Secure Goose: TLS renegotiation vulnerability (CVE-2009-3555) Confidence 2009.02 – My TLS [...]</description>
		<content:encoded><![CDATA[<p>[...] vulnerability and mitigation&#8217; &#8211; MARC Links » Another Protocol Bites The Dust Extended Subset » Blog Archive » Authentication Gap in TLS Renegotiation The Secure Goose: TLS renegotiation vulnerability (CVE-2009-3555) Confidence 2009.02 – My TLS [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Betanews Podcast: Rupert Murdoch and the buying stuff online problem &#124; CHARGED's Digital Lifestyle at Work or Play</title>
		<link>http://extendedsubset.com/?p=8#comment-23</link>
		<dc:creator>Betanews Podcast: Rupert Murdoch and the buying stuff online problem &#124; CHARGED's Digital Lifestyle at Work or Play</dc:creator>
		<pubDate>Wed, 09 Dec 2009 06:16:12 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=8#comment-23</guid>
		<description>[...] Marsh Ray and Steve Dispensa&#8217;s blog entry on the TLS renegotiation problem. [...]</description>
		<content:encoded><![CDATA[<p>[...] Marsh Ray and Steve Dispensa&#8217;s blog entry on the TLS renegotiation problem. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Trys saugumo pataisymai &#124; FreeBSD.lt</title>
		<link>http://extendedsubset.com/?p=8#comment-13</link>
		<dc:creator>Trys saugumo pataisymai &#124; FreeBSD.lt</dc:creator>
		<pubDate>Sat, 05 Dec 2009 12:01:16 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=8#comment-13</guid>
		<description>[...] Prieš kelias dienas oficialiai buvo pranešta apie trijų klaidų esančių FreeBSD sistemoje pataisymus. Pirmoji pataisa skirta šią savaitę paskelbtai kritinei klaidai, kai lokalus vartotojas gali gauti administratoriaus teises. Antroji ištaiso prieigos teisių problemą naudojant freebsd-update programą. Trečioji ištaiso neseniai paskelbtą OpenSSL klaidą. [...]</description>
		<content:encoded><![CDATA[<p>[...] Prieš kelias dienas oficialiai buvo pranešta apie trijų klaidų esančių FreeBSD sistemoje pataisymus. Pirmoji pataisa skirta šią savaitę paskelbtai kritinei klaidai, kai lokalus vartotojas gali gauti administratoriaus teises. Antroji ištaiso prieigos teisių problemą naudojant freebsd-update programą. Trečioji ištaiso neseniai paskelbtą OpenSSL klaidą. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alice Allen</title>
		<link>http://extendedsubset.com/?p=8#comment-10</link>
		<dc:creator>Alice Allen</dc:creator>
		<pubDate>Thu, 05 Nov 2009 14:13:18 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=8#comment-10</guid>
		<description>Here is an article about this discovery by the UK Register just out:

http://www.theregister.co.uk/2009/11/05/serious_ssl_bug/</description>
		<content:encoded><![CDATA[<p>Here is an article about this discovery by the UK Register just out:</p>
<p><a href="http://www.theregister.co.uk/2009/11/05/serious_ssl_bug/" rel="nofollow">http://www.theregister.co.uk/2009/11/05/serious_ssl_bug/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Authentication Gap in TLS Renegotiation &#171; Jasper Blog</title>
		<link>http://extendedsubset.com/?p=8#comment-9</link>
		<dc:creator>Authentication Gap in TLS Renegotiation &#171; Jasper Blog</dc:creator>
		<pubDate>Thu, 05 Nov 2009 12:27:00 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=8#comment-9</guid>
		<description>[...] Read more: Extended Subset [...]</description>
		<content:encoded><![CDATA[<p>[...] Read more: Extended Subset [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Une faille dans le protocole SSLv3/TLSv1 &#171; Criminalités numériques</title>
		<link>http://extendedsubset.com/?p=8#comment-8</link>
		<dc:creator>Une faille dans le protocole SSLv3/TLSv1 &#171; Criminalités numériques</dc:creator>
		<pubDate>Thu, 05 Nov 2009 11:18:51 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=8#comment-8</guid>
		<description>[...] Ray annonce sur son blog qu&#8217;il aurait découvert cette faille lors de travaux pour sa société Phonefactor. Les [...]</description>
		<content:encoded><![CDATA[<p>[...] Ray annonce sur son blog qu&#8217;il aurait découvert cette faille lors de travaux pour sa société Phonefactor. Les [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
