1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

PHP, Python still fail to spot revoked TLS certificates

Discussion in 'Help Net Security' started by RSS, Apr 1, 2016.

  1. RSS

    RSS New Member Member

    In 2012, a group of researchers demonstrated that SSL certificate validation is broken in many applications and libraries, and pointed out the root causes for that situation: badly designed APIs of SSL implementations and data-transport libraries. Four years later, Sucuri Security researchers wanted to check what’s the current situation, and discovered that there have been some improvements, but that PHP, Python and Google Go still fail to check if a TLS certificate has been revoked. … More →

    Continue reading...
     

Share This Page