It's definitely a bit surreal that even a crypto library vulnerability not only has its own web site but that the site is almost indistinguishable, like every other site launched today, from an Apple product announcement page.
HN user
noclip
It seems from the reaction that for Facebook this wasn't just a $2 billion deal but a $3 billion deal — $2 billion in cash, plus $1 billion of Oculus' value wiped out by the announcement.
There's also a possibly-not-completly-wrong table on that other TLS library's website (http://www.gnutls.org/manual/gnutls.html#Selecting-cryptogra...) that takes a stab at estimating the relative security levels of (correctly-used) public key algorithms.
I'm curious as to what it is about Australia that makes these obscenely invasive schemes tenable to the public. It's clear that surveillance agencies in representative governments all over the world want and pursue these kinds of capabilities, but almost none are brazen enough to advocate for them openly. Even fewer can do so and reasonably expect a nonzero chance of success.
That, or slap the affiliate ID for Twitter on the URL.
If you pay for (say) a DS3 line, there's an implicit assumption that you are not going to be pumping 44.736 Mbit/s through it 24/7.
Whoa, whoa, whoa. This is exactly the assumption commercial customers paying for unmetered links are making, otherwise they wouldn't be paying for unmetered links. Not being oversubscribed is supposed to the entire point. If ISPs' business models depend on them being able to break their promises to customers paying for continuously saturated links that's their problem, but they're still on the hook for what they're being paid to provide.
The s_client connection continues but should still report a verify error. On Linux:
Except it isn't failing.
It's not just cURL. It's much bigger, and much worse.
What's more puzzling than the flagrant absurdity of this is why the people involved are content to waste their lives creating these things.
ICANN charges 22 cents per domain. What would you propose the price be lowered to?
You mean to say a company that encrypts users' messages in ECB mode with a fixed key hard-coded into the binary and which was publicly disclosed almost a year ago and hasn't been changed isn't responsible with user data?
"were"
Then there's this:
http://www.rollingstone.com/politics/news/looting-the-pensio...
In case anyone is still curious, part of the encrypted data in those blobs is almost certainly the entire HTTP request sent by the client. A tiny GET with just a Host: header generates a much smaller blob than a normal request with a browser.
Why even bother breaking the crypto? They say right on the site that they use HTTP for public key retrieval so a MITM would simply serve up bogus public keys to the clients.