Information Data Security / Items
More holes found in Web's SSL security protocol
Get Feed- Description
-
More holes found in Web's SSL security protocol
By Robert McMillan
IDG News Service - Security researchers have found some serious flaws in software that uses the SSL (Secure Sockets Layer) encryption protocol used to secure communications on the Internet.
At the Black Hat conference in Las Vegas on Thursday, researchers unveiled a number of attacks that could be used to compromise secure traffic travelling between Web sites and browsers.
This type of attack could let an attacker steal passwords, hijack an on-line banking session or even push out a Firefox browser update that contained malicious code, the researchers said.
The problems lie in the way that many browsers have implemented SSL, and also in the X.509 public key infrastructure system that is used to manage the digital certificates used by SSL to determine whether or not a Web site is trustworthy.
A security researcher calling himself Moxie Marlinspike showed a way of intercepting SSL traffic using what he calls a null-termination certificate. To make his attack work, Marlinspike must first get his software on a ...
- Original URL
Comments
Report ThisTwine is about discovering, collecting and sharing the content that interests you. Learn More
Join TwineStats
- 10 Twines
- 1 Comment
Tags
Source Tags
Community Tags
Who's Interested In This?
-
Nick added to Information Data Security, IP Communications, Electronic Privacy, Information Privacy, internets, Privacy, Data Privacy, surveillance, Infosec Tools, Information Security 4 months ago
Public Comments
-
wunderbarb
3 months ago
Add a Comment- Some HTML is allowed.
- Reply
- Cancel
- Submit
Information Data Security