Major SSL encryption flaw hits the web
By Asavin Wattanajantra,
A ‘major’ vulnerability in SSL (Secure Sockets Layer) authentication has been discovered, potentially leaving web surfers under serious threat.
The authentication gap allows an attacker to perform a ‘man-in-the-middle’ attack, according to security researchers at PhoneFactor.
PhoneFactor claimed that most websites using SSL encryption were affected, including online banking and retail sites. Some mail and database servers were also vulnerable.
It also invalidated the SSL lock, which is used to verify whether website communications are secure.
Researchers Marsh Ray and Steve Dispensa are believed to have shown the flaw to a working group of affected vendors, which included Microsoft, Intel, Nokia, IBM, Cisco and Juniper.
In a statement, PhoneFactor said: “[We] volunteered to delay disclosure on the vulnerability until early 2010 to allow time for vendors to make the necessary patches available."
“However, an independent researcher discovered the vulnerability and posted it to Internet Engineering Task Force (IETF) mailing list on November 4th... News of the vulnerability quickly spread through the IT security community,” it added.
PhoneFactor added that this was a protocol vulnerability rather than an implementation flaw, so the impact was far reaching.
“All SSL libraries will need to be patched, and most client and server applications will, at a minimum, need to include new copies of SSL libraries in their products," the firm said.
“Most users will eventually need to update any software that uses SSL.”
Andrew Clarke, senior vice president for Lumension, said in a statement that the SSL flaw was likely to bring a large number of patches in the near term from vulnerable vendors.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Strategy Analysis & Insight
Q&A: Daniel Reed, Reader's Digest
We spoke to the man in charge of the technology strategy for Reader’s Digest in Europe and Asia Pacific.
- Welcome to the stay-at-home Olympics
- What should RIM do to recapture the attention of businesses?
- Q&A: Colin Bannister, UK CTO, CA Technologies
- Will someone rid me of these troublesome Macs?
- What can Intel bring to the smartphone market?
- Q&A: Cisco on servers, storage and strategy
- Q&A: Raj Samani, CTO McAfee
- Erase and rewind: the EU and privacy
- Does 2012 spell doom and gloom for the tech sector?
Latest Strategy Reviews
ThinPrint Printer Dashboard review: First Look
- Office 365 review: First look
- Novell ZENworks Configuration Management 11 Standard Edition review
- Mindjet MindManager 9 review
- Tableau Desktop Professional Edition review
- Spiceworks review
- Head to Head: Parallels Desktop 6 vs VMware Fusion 3
- Swiftlight review
- FaceTime Communications USG-1030 review
- Top 10 iPad apps for business review
advertisement
Most popular
- Ubuntu vs. Windows 7 on the business desktop
- York researchers heat storage to speed up data
- BlackBerry Bold 9790 review
- OneNote hits Google?s Android
- O2 trials Olympic-scale remote working
- Will someone rid me of these troublesome Macs?
- Lenovo beats expectations again
- Who to trust after the VeriSign hack?
- Google to promise fairness after Motorola buy
- Report: Google cloud storage coming soon
Latest News Videos in Strategy
Q&A: David Elton, PA Consulting Group
CIOs are increasingly influential, but have to juggle "dual roles", study finds.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.






Some words.
At Thawte, we're asserting that patches are already well in the works all around, and that this attack cannot be used to compromise any users private data (it could be used to target databases, but it's doubtful that the MITM attack has ever actually been attempted by malevolent hackers). In brief, developers have some work to do, but online banking and shopping can continue as usual without fear (although the same rules apply, of course, and it's always better to use sites that have extended validation ssl in place).
By johnhilst on Monday Nov 9