Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 27th, 2012, 08:25 AM
lotuseclat79 lotuseclat79 is offline
Very Frequent Poster
 
Join Date: Jun 2005
Posts: 1,958
Default 90% of popular SSL sites vulnerable to exploits, researchers find

90% of popular SSL sites vulnerable to exploits, researchers find.

Quote:
Less than 10 percent of the most popular websites offering Secure Socket Layer protection are hardened against known attacks that could allow hackers to decrypt or tamper with encrypted traffic, researchers said Thursday.

-- Tom
  #2  
Old April 28th, 2012, 11:54 AM
BrandiCandi
 
Posts: n/a
Default Re: 90% of popular SSL sites vulnerable to exploits, researchers find

Quote:
BEAST, short for browser exploit against SSL/TLS, isn't easily eradicated, because patches would make websites incompatible for millions of people using older browsers.
Isn't that interesting?
  #3  
Old April 28th, 2012, 12:19 PM
Wroll Wroll is offline
Frequent Poster
 
Join Date: Nov 2011
Location: Italy
Posts: 231
Default Re: 90% of popular SSL sites vulnerable to exploits, researchers find

Nope, just normal business these days.
  #4  
Old April 28th, 2012, 05:57 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: 90% of popular SSL sites vulnerable to exploits, researchers find

Quote:
Originally Posted by BrandiCandi
Isn't that interesting?
Only the wrong patches. If servers forced TLS standards that aren't supported they would break for browsers that don't support them.
__________________
  #5  
Old April 29th, 2012, 12:16 PM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: 90% of popular SSL sites vulnerable to exploits, researchers find

Quote:
Originally Posted by Hungry Man
Only the wrong patches. If servers forced TLS standards that aren't supported they would break for browsers that don't support them.

I say to hell with all the people out there running IE 6. Either freaking upgrade or get left behind.

Also. I would like to add that some of these researchers who carried out this study are literally the who's who in SSL:

Quote:
SSL Pulse is the brainchild of the Trustworthy Internet Movement, a recently formed group that has chosen SSL as its first project. Members include Ristic; Google Software Engineer Adam Langley; SSL researcher Moxie Marlinspike, whose company was recently acquired by Twitter; Michael Barrett, who is chief information security officer at PayPal; Taher Elgamal, founder and chief identity officer at IdentityMind and a co-creator of the SSL protocol; and Ryan Hurst, chief technology officer at GMO GlobalSign.

Taher Elgamal invented the Elgamal encryption algorithm which is used widely on the Internet. In other words, he is one of the foremost experts in the world on public-key encryption protocols.

Basically, this study confirms what many of us have known for years -- SSL completely and utterly sucks. We need to redesign the system from scratch.

Last edited by chronomatic : April 29th, 2012 at 12:22 PM.
  #6  
Old April 29th, 2012, 02:10 PM
funkydude's Avatar
funkydude funkydude is offline
Incredibly Massive Poster
 
Join Date: Apr 2004
Posts: 6,017
Default Re: 90% of popular SSL sites vulnerable to exploits, researchers find

Quote:
Originally Posted by chronomatic
I say to hell with all the people out there running IE 6. Either freaking upgrade or get left behind.

IE6? You do realize we are STILL waiting for Firefox and Chrome to implement TLS 1.1 & 1.2, right? Websites won't implement something that all browsers can't use, and by the looks of it, Mozilla and Google won't implement something that websites aren't using. Nice loop.

Not to mention the amount of misconfigured servers out there, which is why Microsoft has to turn off TLS 1.1 and 1.2 by default, and also why Google's recent attempt to speed up TLS failed. IE6 really is just a pin in a haystack of issues.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:21 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums