Most Popular Stories
- A 'mobile help desk' in every pocket, from Salesforce.com
- Apple co-founder Wozniak sings Android's praises
- Four ways to better manage IT sales calls
- Section 508 web accessibility rule to change
- Survey finds many users blow by SharePoint security
- How hackers can eavesdrop on prevalent videoconferencing systems
Events
- CIO Summit
March 18- 21 — Miami, FL - Northwestern University Master's in Information Systems
- The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - CIO Healthcare Summit
March 11-14 — Scottsdale, AZ
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Efficiency On Demand
- Durable Smart Devices for Mobile Field Forces: Selection and Evaluation Criteria
- Ensuring Cultural Adoption
- Is Corporate Liability Robbing YOU Blind?
- The Top 4 Reasons Your Telecom Expense Management Provider Shouldn't Manage Your Wireless
Crippling SSL vulnerability discovered
A serious security flaw has been discovered in the SSL protocol, commonly used to encrypt web pages in order to secure online transactions against eavesdropping or interception. The problem was originally discovered by security researchers Marsh Ray and Steve Dispensa at PhoneFactor, who originally planned to disclose it only next year. The delay was meant to give security vendors sufficient time to fix their products.
However, the same vulnerability was discovered by an independent security researcher, who promptly posted about it on an Internet Engineering Task Force mailing list. As you can imagine, that blew Pandora's Box wide open, prompting PhoneFactor to come forward with the details of its findings.
The vulnerability in SSL is particular crippling because it is a protocol weakness, and not the fault of a programmer who implemented a code library wrongly. In a nutshell, all encryption technology that relies on SSL is affected by the vulnerability, and is open to eventual exploitation. Basically, it is now possible for an attacker with the right tools to execute a man-in-the-middle attack to hijack a bona fide SSL session.
To underscore the severity, Steve Dispensa wrote in a statement: "All SSL libraries will need to be patched, and most client and server applications will, at a minimum, need to include new copies of SSL libraries in their products. Most users will eventually need to update any software that uses SSL."
You can check out their blog here for more information.
For more on this story:
- check out this article at InformationWeek
Related Articles:
Researchers poke holes in EV SSL
Researchers demonstrate more physical ways to spy on keystrokes
Just launched IE 8 successfully hacked
$10,000 cash prize for smartphone hacks
Related Stories
- Just one security bulletin for Patch Tuesday in May
- RSA tells more about SecurID breach
- Researchers demonstrate bypass of IE Protected Mode
- McAfee: Malware at all-time high
- Latest iPhone jailbreak concerns security experts
- New study says cybercrime costs enterprises $3.8 million a year
- Mozilla ups security bug bounty to $3,000
- Microsoft to patch XP Help hole, four other vulnerabilities next Tuesday
- Microsoft confirms critical Windows XP bug, recommends workaround
- WiFi key-cracking kits being sold in China
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




