Ticket #756 (new Defect)
Unsecure SSL connection
| Reported by: | anonymous | Owned by: | timothy |
|---|---|---|---|
| Priority: | Highest | Milestone: | Colloquy 2.4 |
| Component: | Chat Core (IRC) | Version: | 2.3 (Mac) |
| Severity: | Blocker | Keywords: | |
| Cc: | colloquy@… |
Description (last modified by rinoa) (diff)
I find SSL connection handling in Colloquy unsecure. Server's SSL certificate is not checked for validity and as such the connection could be compromised by man in the middle attack.
Colloquy should prompt the user about invalid certificate or at least there should be an option to turn such check on.
I find this critical as it prevents using Colloquy in certain security driven scenarios.
Change History
Note: See
TracTickets for help on using
tickets.
