It has now been twelve years since the paper "The most dangerous code in the world: validating SSL certificates in non-browser software" was published.
My blog post about it from back then: daniel.haxx.se/blog/2012/10/25…
It'd be interesting to know how much HTTPS clients are still skipping cert verification in the wild. I bet it is still widespread.
libcurl claimed to be dangerous
On October 24th, my twitter feed suddenly got more activity than usual when suddenly there's a mention of a newly(?) published paper: The most dangerous code in the world: validating SSL certificates in non-browser software Within the twelve page doc…daniel.haxx.se
))
Ramon Fincken 🇺🇦
in reply to daniel:// stenberg:// • • •Stefan Eissing
in reply to daniel:// stenberg:// • • •