Forum Moderators: open

Message Too Old, No Replies

Mozilla will patch zero-day Firefox bug Sept. 20

         

bill

12:13 am on Sep 19, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Mozilla will patch zero-day Firefox bug to fiddle man-in-the-middle diddle [theregister.co.uk]

"Firefox uses its own static key pinning method for its own Mozilla certifications instead of using HPKP. The enforcement of the static method appears to be much weaker than the HPKP method and is flawed to the point that it is bypassable in this attack scenario."

Mozilla will push the fix into its stable release version on 20 September.