Zero-day flaw found in web encryption
news.zdnet.co.uk
news.zdnet.co.uk
I think that x509 client auth is probably underused due to the lack of good, free implementations of CA software to manage those certificates.
Unfortunately, that's all the data I have on that, that one sentence, and a few other places that have the same basic info which may or may not simply be reflections of this one. I haven't seen any additional substantiation.
What's also true is that there are lots of protocols, many of them very obscure, that either rely on client auth, or that may themselves have an app-layer notion of multiple sessions which will conflict with TLS's session renegotiation.
I'm not going to eat my hat or anything if this happens, but I'd bet againt someone finding a plausible MITM attack that beats server certificates using this attack. I think it's reasonably safe shorthand right now to say this attack largely applies to apps that use SSL outside of its common case.
From wiki: "Zero-day attacks occur when a vulnerability window exists between the time a threat is released and the time security vendors release patches."
A flaw exists. No released patches yet.
I'm not quite convinced by the Wiki quote though; more than once, I've heard 0-day attacks to mean a vulnerability found on the day a new version of a software is released. Perhaps both meanings exist.
I've never heard that meaning. It doesn't really make sense - why would someone care if the vulnerability was the same day of the new version or not? (Except to show off.)
Zero day to me, means it's the first day after the vulnerability was found. i.e. it's a brand new vulnerability, and no one else knows about it or has a defense for it. (It being assumed that all vulnerabilities are fixed the day they are found.) Extending it to mean "until it's fixed" makes sense too when dealing with certain vendors who don't fix things very fast.
There are as many different definitions of zeroday in the security scene as there are people with strong opinions, but all the definitions boil down to, "it's zeroday if it's new". There's patched zeroday (when SUNW releases code that fixes a flaw and they don't tell anyone about it, the exploit for that flaw is zeroday). Unpatched flaws are usually by definition zeroday.
It's kind of a silly thing to argue about, since there's no consensus definition. This TLS flaw definitely qualifies by most people's definitions.