| Distinguished Member with 21,345 posts. | | Join Date: Sep 2003 Location: -71.45091, 42.27841 | |
More Holes Found in Web's SSL Security Protocol More Holes Found in Web's SSL Security Protocol. Security researchers have found some serious flaws in software that uses the SSL (Secure Sockets Layer) encryption protocol used to secure communications on the Internet. Quote:
At the Black Hat conference in Las Vegas on Thursday, researchers unveiled a number of attacks that could be used to compromise secure traffic travelling between Web sites and browsers.
This type of attack could let an attacker steal passwords, hijack an on-line banking session or even push out a Firefox browser update that contained malicious code, the researchers said.
The problems lie in the way that many browsers have implemented SSL, and also in the X.509 public key infrastructure system that is used to manage the digital certificates used by SSL to determine whether or not a Web site is trustworthy.
| -- Tom |