
Sign up to save your podcasts
Or


"CurveBall" is a spoofing vulnerability in the way the certificates are accepted without proper verification of the explicit curve parameters within the certificates. Essentially, this flaw allows an attacker to supply his own generated X.509 certificates by using an "explicit parameters" option to set those curve parameters.
Subscribe & watch the full Podcast:
https://twit.tv/sn/750
Hosts: Leo Laporte and Steve Gibson
You can find more about TWiT and subscribe to our full shows at https://twit.tv/shows/
By TWiT4.7
2323 ratings
"CurveBall" is a spoofing vulnerability in the way the certificates are accepted without proper verification of the explicit curve parameters within the certificates. Essentially, this flaw allows an attacker to supply his own generated X.509 certificates by using an "explicit parameters" option to set those curve parameters.
Subscribe & watch the full Podcast:
https://twit.tv/sn/750
Hosts: Leo Laporte and Steve Gibson
You can find more about TWiT and subscribe to our full shows at https://twit.tv/shows/

9 Listeners

34 Listeners

109 Listeners

6 Listeners

139 Listeners

29 Listeners

96 Listeners

35 Listeners

72 Listeners

116 Listeners

94 Listeners

24 Listeners

50 Listeners

15 Listeners

10 Listeners

9 Listeners

0 Listeners

28 Listeners

31 Listeners

0 Listeners