Newsletters Welcome, Guest Log In | Register

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

0

Black Hat Researchers Unveil Serious SSL Flaws

Posted by Kara Reeder Jul 30, 2009 10:47:42 AM

Security researchers at the Black Hat conference unveiled some serious flaws in software that uses the SSL encryption protocol, reports PCWorld.

 

One researcher calling himself Moxie Marlinspike demonstrated a way of intercepting SSL traffic using what he calls a null-termination certificate. He claims his man-in-the-middle attack is undetectable. According to Marlinspike, the diabolical thing about his tool that intercepts the Firefox auto update requests is that even the update mechanisms cannot be trusted, notes CNET News.

 

In addition, researchers Dan Kaminsky and Len Sassaman say that they found that a large number of Web programs use certificates issued with an obsolete cryptographic technology, called MD2, that has long been considered insecure. While MD2 has not actually been cracked, it could be broken by a determined attacker.

Add a comment Leave a comment on this blog post.

There are no comments on this post

Budget & Finance Toolkit for IT - 2010 Edition

What kind of year are you planning in 2010?  Growth or continued "survival mode"?  Download a comprehensive collection of templates, forms, instruction and advice that will help you to plan and submit your 2010 IT Budget.

Learn more >

All About Reducing Your IT Costs

Looking to cut costs? Use this research-driven Excel tool to pinpoint which IT cost reduction measures best fit your needs.

Learn more >

Lowering Your IT Costs with Oracle Database 11g Release 2

This white paper identifies the key capabilities a database management solution needs to successfully deliver more information with higher quality of service, make more efficient use of IT budgets, and reduce the risk of change in data centers.

Software Forum: Information On Demand Virtual Experience

This interactive virtual forum presents leading IT experts providing the insights you need to turn your information into a strategic driver for innovation, business optimization and competitive differentiation.

Tablet PCs

Powerful and portable computing capacity for today's high-speed, fluid business environment.

Data Management

Data management tips and techniques that insure ease of access, comprehensive security and absolute privacy for your invaluable company information.

Mobile Computing Optimization

Mobile computing solutions, tips, and expert commentary that increases the usability and bottom-line benefits of your mobile computing assets.

Network Optimization

Network management tools and tips to increase network speed and efficiency, regardless of office location.