Showing posts with label SSL. Show all posts
Showing posts with label SSL. Show all posts

Friday, 18 September 2015

Google Will Support SSL 3.0 And RC4 Off



Google goes off in the medium term to support SSL 3.0 and RC4, which can affect systems that encrypted communicate with Google's servers. SSL 3.0 is now more than 16 years old and is for instance no longer supported in Google Chrome.

RC4 dating from 1987, is an algorithm that is used for setting up an encrypted connection. Both techniques are considered unsafe. Reason for Google to support SSL 3.0 and RC4 on the front-end servers to go off switch, so let Google engineer Adam Langley know. The Internet giant expects some problems with it. A survey among 200,000 most popular websites with HTTPS indicate that 58% still supports RC4 and 35% SSL 3.0.

The frontend-servers of Google are not only visited by Internet users via their browser. Communicate many embedded systems as well as any servers using SSL / TLS with Google's servers. If Google later with the support of SSL 3.0 RC4 and stops can cause problems. Therefore, the Internet giant has today established a minimum standard TLS TLS which clients must meet.

It may then go on to clients that use TLS for HTTPS, but also SMTP servers (mail servers) that use it for STARTTLS. According to Google, the new requirements would probably have to last until 2020. "But we can not predict the future," said Langley. To help organizations there is a special website set up that can be tested or to a part of the requirements are met.

Thursday, 5 March 2015

New TLS / SSL Leak Hits Android And Apple Users


Researchers have discovered a new leak in TLS / SSL encrypted connections allowing attackers from Android and Apple users attacks. The problem that the name " FREAK Attack "has been, in some TLS / SSL servers and present clients, and allows an attacker located between the target and the Internet is the security of the TLS connection to a weak encryption can downgrade . Then this encryption can be attacked and content viewed from the protected traffic.

The vulnerability is caused by the US export policy in the early 1990s, making strong encryption could not be exported.Instead, there was only "export-grade" RSA encryption are supplied. The encryption keys were in this case only 512-bits wide.According cryptography professor Matthew Green was the 512-bit export-grade encryption weigh "dumb and dumber". "In theory was developed to ensure that the NSA communication could approach, while there could also be argued that the cryptography" "for commercial use." Good enough

According to Green led the need to support export-grade encryption to technical challenges. American servers were namely support both strong and weak encryption. The SSL developers were using a mechanism to set up a secure connection between two parties support the strongest encryption chooses which both parties. In theory, American users with American servers than strong encryption can use, while foreign clients with weak encryption are supported.

Most modern clients, such as browsers, would be to set up an encrypted connection is no export-grade encryption offer more.In addition, it was assumed that most servers nor export-grade encryption would offer more. Furthermore, an attacker in case there are still export-grade encryption for the encrypted compound was used must compute a 512-bit RSA key.

Researchers at Microsoft Research and INRIA IMDEA discovered that some modern TLS clients, including Apple's Secure Transport and OpenSSL, contain a vulnerability. Therefore they accept RSA export-grade encryption, even though they did not ask for this. According to Green, this bug has major consequences, since the attacker will connect to downgrade.However, the client in question need to be vulnerable, and the support server export-grade RSA. Contrary to what many people thought was export-grade RSA still in use. 36.7% of the 14 million websites investigated were found to support it.

"We thought that people were using it anymore," said Karthikeyan Bhargavan, a researcher from the French computer lab INRIA opposite the Washington Post . The team Bhargavan discovered the problem during testing of encryption systems.According to Nadia Heninger, a cryptographer at the University of Pennsylvania, we have here is actually a "zombie from the 1990s" to make. Heninger says that she can crack the export-grade encryption through the Amazon Web Services in 7 hours.

The vulnerability was already patched OpenSSL in January this year. Apple would now working on an update next week, and several internet parties are working to export-grade encryption to phase out. Google would now also have rolled out a patch among suppliers. However, it is up to these parties to the Android update to roll out among their users. Android users also get the advice to use a browser other than the one that comes standard.

Wednesday, 21 January 2015

Oracle Java SSL 3.0 Switches Off


To protect users from attack Java, Oracle SSL 3.0 disabled in the software. The measure is part of the security update that appeared Tuesday. "This Critical Patch Update disables the standard use of SSL 3.0. SSL 3.0 will be considered an obsolete protocol and this situation is exacerbated by the POODLE-leak. As a result, this protocol widely attacked by malicious hackers," says Eric Maurice Oracle.

The POODLE-vulnerability in SSL 3.0 ensures that an attacker who between a user and the Internet to know places, for example in an open Wi-Fi network, can steal information from encrypted connections, such as session cookies. Maurice gives organizations advised to discontinue use of all SSL versions, as it is no longer the safe communication between systems can be trusted.

Also Oracle customers have to change their code and switch to a more secure protocol such as TLS 1.2. Oracle employee further notes that Oracle in the future SSL in all Oracle software will turn off. Besides disabling SSL 3.0 update also fixes 19 vulnerabilities in Java, which in the worst case, an attacker can give full control over the system.

Saturday, 12 April 2014

NSA for 2 years at the height of Heart Bleed

According to the U.S. News Agency Bloomberg NSA was familiar with the Heart Bleed bug for 2 years and she has the vulnerability in OpenSSL frequently used to gather information. Bloomberg cites sources that are "aware of the situation" are.
The decision of the NSA to keep the secret bug in the framework of national security interests, the debate about the role of computer experts from the U.S. government, revived considerably. Again
Heart Bleed seems one of the biggest leak in the history of the Internet to have. As many as two-thirds of the world's websites is touched. The discovery and the advisory that five days ago was published by researchers has led to massive consumers have changed their passwords, the Canadian government has postponed the electronic tax return and that large technology companies such as Cisco Systems and Juniper Networks patches for their systems released. There are also a lot of new SSL certificates issued.
The Heart Bleed bug quietly adding to the arsenal, the NSA has been able to obtain. Passwords and other important information The price for this was high. Millions of ordinary users are left to their own and all that time was vulnerable to attack by secret services and cyber criminals.
Jason Healey, director of the "cyber statecraft initiative at the Atlantic Council" and a former Air Force officer explains: "The security community will not chip them really leave after this revelation."
The NSA has just been denied before the vulnerability became public last week. Bleed Heart of informed on twitter


Wednesday, 9 April 2014

Fake poll as a lure for Facebook Phishing Scam

The Facebook application asks users to register their votes

Cyber criminals have again found a new way to Facebook to trick users into entering their login details. They run a fake online poll for the purpose of luring. Potential victims to a phishing site.

A pop-up window requesting for user account information

Symantec reports that the scammers run an online poll with the question: "Who better boys or girls" Once the visitor has cast his vote will be prompted to log in to the Facebook account and asked whether the visitor is male or female. After logging the victim sees the message that his voice has been sent. Scammers host the site on a subdomain ([http://] Smart Apps. [deleted]. com) to indicate that it is an application and the to appear. matter professionally in this context is the number of voters also raised periodically.

A comparison of the previous vote count and the current vote count

While it does seem that way at first glance Facebook has nothing to do with the campaign. When visitors log in reality they give their login information to the cyber criminals.

The scammers probably realize only too well that many Facebook users, this kind of thing every day without too much thought do. It is not inconceivable that they have already succeeded in many account data store.

Prevent
To a victim of a Facebook scam to be, it is important that you never put your password on domain other than facebook.com enter. The real login page of Facebook is secured with an SSL certificate which can be used by the padlock in the address bar of the browser and the HTTPS recognized connection.

Sunday, 16 March 2014

Phishing Attack on Google users hosted by Google

In a recent phishing attack on users of Google Docs and Google Drive cybercriminals have the phishing page where victims had to introduce hosted on the servers of Google. Their credentials Something the phishing attack is both refined and remarkable, says Symantec.

Google Docs phishing login page

The anti-virus company discovered the attack, which starts with an email subject "Documents" has. The email prompts the recipient to view an important document. The link does not point to Google Docs, but after a fake Google login page. The neppagina however hosted on Google's servers and then ran over an SSL-secured connection, which makes the attack seem more convincing.
In this case, the scammers a folder in a Google Drive account is created, placed it in a file and then put the public folder. The preview feature of Google Drive they got this way a publicly accessible URL that was added. To the phishing emails When users their information on the phishing page fill go directly to the criminals behind the attack, while the victim to the real Google Docs page is redirected and possibly nothing by it.