(the part about it being a spec flaw is BS - the spec is vague but a properly defensive implementation wouldn't be vulnerable)
-
-
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
I need to review the patches but the general idea is a failure to track the state of the handshake AIUI. The zero-key part is def. a bug.
-
Ultimately though, if you can patch it without breaking the spec (which you can), by definition it's not a spec bug but an impl bug.
End of conversation
New conversation -
-
-
Regular testing does not catch security flaws.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.