miTLS - Home edit / delete

A formally verified implementation of TLS. (Being written in F# means it's a bit impractical to use as a library, though...)

to cryptography formal-methods security tls verification ... on 28 April 2014

BetterCryptoâ‹…org edit / delete

Practical recommendations for TLS settings.

to cryptography security ssl tls ... on 28 April 2014

Diffie Hellman and TLS with nonsense parameters - Hanno's blog edit / delete

Apparently quite a lot of TLS implementations will happily accept 15 as a prime for DH key exchange. Presumably even if they were checking you could rely on the probabilistic test too...

to cryptography dh prime security ssl testing tls ... on 16 April 2014

Embedded in Academia : A New Development for Coverity and Heartbleed edit / delete

What Coverity is doing to detect the Heartbleed problem (in short: treating n2hs-style functions as generating tainted results).

to coverity security ssl static-analysis tls ... on 14 April 2014

Using Frankencerts for Automated Adversarial Testing of Certificate Validation in SSL/TLS Implementations edit / delete

Generating randomly-varied certificates and comparing how different implementations respond to them.

to ca certificate papers security ssl testing tls ... on 13 April 2014

ImperialViolet - Apple's SSL/TLS bug edit / delete

The famous copy-and-paste error.

to ag0700 goto security ssl tls ... on 25 March 2014

Moserware: The First Few Milliseconds of an HTTPS Connection edit / delete

Nice overview of what exactly is going on when establishing a TLS connection, with packet dumps and brief explanations of the maths.

to ag0803 crypto dump networking packet ssl tls ... on 17 December 2013

About Crossbear | pki.net.in.tum.de|crossbear.org edit / delete

"Crossbear is a tool that aims to detect and localise Man-in-the-middle (MitM) attacks on the SSL/TLS [and SSH] protocols." It works by comparing the certificate you get with what others got from different locations. (I imagine CDNs will break this as usual...)

to ca certificate security ssh ssl tls ... on 14 December 2013

ioerror/tlsdate edit / delete

Set the clock from the timestamp in a TLS handshake. Not a million miles away from my 404date script, although about a thousand times more complicated!

to software time tls ... on 14 December 2013

TLS SNI Test Site: bob.sni.velox.ch edit / delete

Test whether your browser supports SNI.

to http https security sni ssl tls ... on 29 June 2011

Browser bookmarks: tasty+ | tasty= Log in | Export | Atom