last updated at 2009-11-15 21:40
PovAddict: "Since this will be one of the more widely-implemented and used HTTP APIs out there, it would be good to have feedback from the HTTP community." -- Mark Nottingham
melvster: successfully targeted the so-called SSL renegotiation bug to steal Twitter login credentials that passed through encrypted data streams
melvster: Twitter proved an ideal platform to carry out the attack for several reasons. First, every request sent over the microblogging site includes the account holder's username and password.
melvster: Twitter's security team closed the hole earlier this week.
