back
2 comments
Unless you are using client side certificates, this one is not your problem.

But everybody must upgrade their browsers ASAP.

Well, Firefox and Chrome use NSS, IE uses SChannel. Not sure about Safari or mobile browsers, but I believe the majority of desktop browsers will be safe.
Safari uses Apple's own TLS library, SecureTransport. Apple deprecated OpenSSL long ago.
Is that right? My reading of it is that this affects all cases where you verify the certificate
It's right and wrong.

It's wrong in that this is very much your problem. It's right in that there is nothing you can do about it except hope that all the people who might try to connect to your website are using a patched (or pre-broken) verison of OpenSSL.

Patching your server-side version of OpenSSL (while a good idea) will not solve the problem because certificate verification is done (as it must be) browser-side.

Yes and most web servers do not use client certificates and do not have any need to validate certificates.
Yes but in practice a lot of them do, for example, when they download a library from PyPI or rubygems...? Unless we're talking just about when people use client certificates as authentication?
> PyPI or rubygems

These are not activities which a web server does though.

These are activities usually triggered by developers or administrators, not by web servers remotely and they have to do with a web application, not a web server.

And even then, for this attack to be meaningful you'd need to have active MITM between the server and PyPI or rubygems at the time when the developer or administrator was updating this. In a good datacenter, this should not be possible. Employees of the DC and national security agencies, which may be able to perform active attacks in such datacenters would probably be the biggest risk.

>And even then, for this attack to be meaningful you'd need to have active MITM between the server and PyPI or rubygems

Yeah. Which is pretty much the thing (or one of the things anyway) that TLS is supposed to prevent!

>These are activities usually triggered by developers or administrators, not by web servers remotely and they have to do with a web application, not a web server.

Some strange distinctions. A server running a web application may well want to make requests to PyPI when being provisioned.

This should only be the case for the build server that creates the packages that get installed on production.
Any proxy or loadbalancer that uses https should validate certificates, however.
SSL does not necessarily mean OpenSSL is involved, but it could. Follow the advisories.