Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update hoauth #42

Open
jgoerzen opened this issue Jul 20, 2012 · 0 comments
Open

update hoauth #42

jgoerzen opened this issue Jul 20, 2012 · 0 comments

Comments

@jgoerzen
Copy link
Owner

Rudiger, Daiki, Aditya, and John:

I know you aren't all choosing to use SSL, but I think you're all
using hoauth in packages on Hackage:
http://hackage2.uptoisomorphism.net:8080/package/hoauth/reverse

You should probably bump the requirement to hoauth >= 0.3.4. That
version, which Diego uploaded a month and a half ago, includes a patch
of mine which turns the SSL certificate verification back on.
Programs compiled with earlier versions would still be vulnerable to
man-in-the-middle attacks even when using SSL... And I think you're
all still allowing older versions than that.

Anyways, cheers, and happy coding!

KevinRudiger, Daiki, Aditya, and John:

I know you aren't all choosing to use SSL, but I think you're all
using hoauth in packages on Hackage:
http://hackage2.uptoisomorphism.net:8080/package/hoauth/reverse

You should probably bump the requirement to hoauth >= 0.3.4. That
version, which Diego uploaded a month and a half ago, includes a patch
of mine which turns the SSL certificate verification back on.
Programs compiled with earlier versions would still be vulnerable to
man-in-the-middle attacks even when using SSL... And I think you're
all still allowing older versions than that.

Anyways, cheers, and happy coding!

Kevin

Kevin Cantu

Kevin Cantu
805-669-8778

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant