top | item 8592467

(no title)

xnull | 11 years ago

The window from disclosure of patches to duplication is narrowing and it appears from the bulletin that client connections are affected as well. Furthermore any computer you take anywhere outside your home router (and can you really trust your home router as security boundary nowdays?!) will be easy to manipulate into an SChannel connection. Inside your home network, clients are still vulnerable to attack - any javascript/flash ad/referer can point a computer behind a router at an attacker server and serve up malicious SChannel packets. That is to say your home computer can be attacked on outgoing connections which your router will be happy to allow.

It's very serious. Patch immediately.

discuss

order

ars|11 years ago

Does this also affect firefox on XP? Does firefox use the Windows TLS library, or does it have its own?

xnull|11 years ago

It has its own ("Network Security Services" or NSS).

But that's not a reason to use Firefox on XP. ;)