Hackers break SSL encryption used by millions of sites

Discussion in 'other security issues & news' started by tlu, Sep 20, 2011.

Thread Status:
Not open for further replies.
  1. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    97,865
    Location:
    U.S.A.
    Removed Off Topic Posts. If we can just concentrate on the topic, and not each other, this thread can continue to live.
     
  2. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
  3. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    I seriously doubt the validity of that proposition.
     
  4. tlu

    tlu Guest

    Care to explain why?
     
  5. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Even Firefox devs agree with me, heh. It's funny though how others seem to rush to the defence of Java, "here we go again", but now its the turn of the Firefox devs.

    Now, although this isn't the best approach to solve this particular problem (TLS 1.1 and 1.2 need to be pushed into use), Java in general needs to be phased out from the web and kept as a system only application, not a web application.
     
  6. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
  7. vasa1

    vasa1 Registered Member

    Joined:
    May 1, 2010
    Posts:
    4,417
    Read the second quote in the link below again before making further comment:
    https://www.wilderssecurity.com/showpost.php?p=1946323&postcount=73
     
  8. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    I did, thanks.

    Yup, sounds about right for another reason to phase out Java, and why the devs want it gone.

    Were you trying to make a point? :rolleyes:
     
  9. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Java will never be phased out. It's been developed too long, it's an incredibly popular language, and it's 100% cross platform.

    Firefox devs aren't going to remove it.

    And really why should they? Instead of just pulling Java it should just be secured further.
     
  10. Escalader

    Escalader Registered Member

    Joined:
    Dec 12, 2005
    Posts:
    3,710
    Location:
    Land of the Mooses

    Thanks fax!:thumb:

    FWIW

    I have ie 9 and W7 64 bit.

    and all ticked 1.0,1.1 and 1.2.

    When I took 1.0 out (no tick) my OLB site won't work.

    The MS link did warn that some sites needed 1.0 and I have that situation.
     
  11. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    ALL sites need TLS 1.0 or SSL 3.0, BOTH are affected by Beast. Do NOT untick 1.0 or you're forcing websites to use SSL 3.0 which is older.
     
  12. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    97,865
    Location:
    U.S.A.
  13. TheKid7

    TheKid7 Registered Member

    Joined:
    Jul 22, 2006
    Posts:
    3,576
    What are your Opinions/Comments? Would you use QuickJava with Firefox as a "fix" for this issue?

    Thanks in Advance.
     
  14. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
    I'd consider using QuickJava if you use Java in the browser infrequently. You could instead disable the Java plugin manually in Firefox, but then you have to remember to disable it when no longer needed if you enabled it. Either way, it's a "fix" in the same sense as Mozilla's proposed fix, but you retain the flexibility to use the Java plugin if desired (assuming Mozilla doesn't implement this proposal).
     
  15. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
  16. Escalader

    Escalader Registered Member

    Joined:
    Dec 12, 2005
    Posts:
    3,710
    Location:
    Land of the Mooses
    As before, I now have

    TSL 1.0, 1.2 and 1.3

    NONE of the SSL's are ticked.

    Using IE9 W7 64 bit
     
  17. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
  18. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Cool, thanks.
     
  19. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Great, wonder what Mozilla is thinking now. I always thought they were in for free user choice until that proposal.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.