http://arstechnica.com/security/news/2009/11/https-ssl-attack-vector-discovered-fix-is-on-the-way.arsI just wanted to put this on the Mina team's radar in case there is
anything you can do about it. I don't know if you could do much about
it the guts of the fix would need to go in the JDK's SSLEngine though
(I'm not sure yet - haven't looked in to it that deeply). Still, I
wanted to pass along if you hadn't heard about it yet.
Regards,
Les