Jonathan Katz jkatz at
Wed Nov 11 10:57:04 EST 2009

Anyone care to give a "layman's" explanation of the attack? The 
explanations I have seen assume a detailed knowledge of the way TLS/SSL 
handle re-negotiation, which is not something that is easy to come by 
without reading the RFC. (As opposed to the main protocol, where one can 
find textbook descriptions.)

