fighting for truth, justice, and a kick-butt lotus notes experience.

POODLE reloaded and there will be Fix for it

 Dezember 12 2014 08:26:17 AM
Because there are some discussions in the Blog-o-Sphere about the poor SSL implementation in Domino, I would like to share the following regarding the new variation of the POODLE attack.

Details about the new POODLE variation can be found here:

German: http://www.heise.de/newsticker/meldung/Poodle-beisst-Load-Balancer-Lueckenhafte-Internet-Verschluesselung-mit-TLS-SSL-2482929.html
English: https://www.imperialviolet.org/2014/12/08/poodleagain.html

Yes, I agree IBM had slept for more then ten years to keep the SSL/TLS stuff up to date, but I can only tell you:

IBM is aware of this bad situation and they are heavily working on it to get it fixed.


via Twitter:

Image:POODLE reloaded and there will be Fix for it

Just cann't say more at the moment, but just wait...


Kommentare

1Dragon Cotterill  12/12/2014 1:46:47 PM  POODLE reloaded and there will be Fix for it

"just wait" - Errr. nope. There are companies out there that have to pay "fines" for being non-compliant with their connections. Thanks to the stupid way that credit card merchants have their rules, if you have a non-compliant connection your card processing fees go up. And at this time of year, this is not acceptable. Get a reverse proxy (NGINX) in place for the time being whilst IBM sit and twiddle their thumbs as usual.

2Detlev Poettgen  12/12/2014 3:54:28 PM  POODLE reloaded and there will be Fix for it

I understand your point, but the other big ones (F5 for example) have to deliver a fix too.

I only want to send a message, that IBM is not blind about this issue.

You can use a reverse proxy like IBM Mobile Connect for sure for HTTP.

But there are all the other protocolls like IMAP, POP3, SMTP or LDAP where IBM should and will have to deliver a Fix.

  •  
  • Hinweis zum Datenschutz und Datennutzung:
    Bitte lesen Sie unseren Hinweis zum Datenschutz bevor Sie hier einen Kommentar erstellen.
    Zur Erstellung eines Kommentar werden folgende Daten benötigt:
    - Name
    - Mailadresse
    Der Name kann auch ein Nickname/Pseudonym sein und wird hier auf diesem Blog zu Ihrem Kommentar angezeigt. Die Email-Adresse dient im Fall einer inhaltlichen Unklarheit Ihres Kommentars für persönliche Rückfragen durch mich, Detlev Pöttgen.
    Sowohl Ihr Name als auch Ihre Mailadresse werden nicht für andere Zwecke (Stichwort: Werbung) verwendet und auch nicht an Dritte übermittelt.
    Ihr Kommentar inkl. Ihrer übermittelten Kontaktdaten kann jederzeit auf Ihren Wunsch hin wieder gelöscht werden. Senden Sie in diesem Fall bitte eine Mail an blog(a)poettgen(punkt)eu

  • Note on data protection and data usage:
    Please read our Notes on Data Protection before posting a comment here.
    The following data is required to create a comment:
    - Name
    - Mail address
    The name can also be a nickname/pseudonym and will be displayed here on this blog with your comment. The email address will be used for personal questions by me, Detlev Pöttgen, in the event that the content of your comment is unclear.
    Neither your name nor your e-mail address will be used for any other purposes (like advertising) and will not be passed on to third parties.
    Your comment including your transmitted contact data can be deleted at any time on your request. In this case please send an email to blog(a)poettgen(dot)eu

Archive