It's not clear if the JRE6 and the JRE7 are impacted (does the JSSE shipped with them support TLS1.2)? If so, pretty worrying as not supported anymore yet widely deployed.
SLOTH – Security Losses from Obsolete and Truncated Transcript Hashes
21–22 of 22 posts
Re: SLOTH – Security Losses from Obsolete and Truncated Transcript Hashes
#22Earlier quoted context omitted.
Oh yeah, they're kicking ass on every front of this sub-field. Then, Leroy et al are doing that for compilers and language analysis at INRIA as well. Then Astree is leading it for static analysis of C. France, esp INRIA, seems to be in the lead on verified software with a real-world focus. It will be great when more elsewhere follow suit.
Galois just gave a talk on high assurance crypto at RWC (they made cryptol and other open sourced tools to give formal proofs of security)
Scrolling their blog is endless insights https://galois.com/blog/
CRYPTOL's open source page http://www.cryptol.net/
SMACCMPilot has things like Ivory language http://smaccmpilot.org/
GitHub site with 8 pages worth of their stuff https://github.com/galoisinc