logoalt Hacker News

The most dangerous code: Validating SSL certs in non-browser software (2012) [pdf]

11 pointsby ripelast Tuesday at 6:45 PM2 commentsview on HN

Comments

philipwhiuklast Tuesday at 7:11 PM

[2012]

The situation has improved somewhat, although some of the underlying libraries have changed little so it's still easy to write insecure TLS.

cURL's API was improved in 7.66.0 for example: https://github.com/curl/curl/pull/4241

But the Java APIs are likely little changed.

show 1 reply