curl-library
Fraudulent Certificates
From: Daniel Stenberg <daniel_at_haxx.se>
Date: Thu, 24 Mar 2011 09:22:58 +0100 (CET)
Date: Thu, 24 Mar 2011 09:22:58 +0100 (CET)
Hi friends,
There's this incident that has been talked about the last couple of days where
"an attacker" managed to get several fraudulent SSL certificates for public
websites.
Chrome and Firefox now both block these certificates explicitly.
I assume there's reason for us to consider doing the same, to protect our
users who might use libcurl to access such sites.
I'll appreciate feedback and ideas.
More details:
http://blog.mozilla.com/security/2011/03/22/firefox-blocking-fraudulent-certificates/
-- / daniel.haxx.se ------------------------------------------------------------------- List admin: http://cool.haxx.se/list/listinfo/curl-library Etiquette: http://curl.haxx.se/mail/etiquette.htmlReceived on 2011-03-24