메뉴 건너뛰기

XEDITION

Board

Newly Found Online Security Flaw Stems From 1990s

BeatrizLarios71259 2022.05.11 08:33 조회 수 : 4

Newly found online security flaw stems from 1990s

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday.

The flaw dubbed "FREAK" could leave thousands of websites open to attacks if the problem is not patched, according to papers released by French and US researchers.

The flaw was discovered by a team led by Karthikeyan Bhargavan at INRIA in Paris -- the French Institute for Research in Computer Science and Automation -- and disclosure coordinated by Matthew Green, a cryptographer at Johns Hopkins University.

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday ©Thomas Samson (AFP/File)

A research paper said the flaw comes from "a class of deliberately weak export cipher suites... introduced under the pressure of US government agencies to ensure that the NSA would be able to decrypt all foreign encrypted communication."

Green said in a blog post that even some sites maintained by the National Security Agency and FBI appeared to be vulnerable.

"Since the NSA was the organization that demanded export-grade crypto, it's only fitting that they should be the first site affected by this vulnerability," Green said.

Green and other researchers said the flaw stems from US government-imposed standards for encryption in software that was exported -- a short-lived effort to allow the United States to be able to access software exported to unfriendly regimes.

- Part of the software -

Even after it became legal to export strong encryption, the export mode feature was not removed from because some software still depended on it, according to Ed Felten, a Princeton University computer science professor.

"The flaw is significant in itself, but it is also a good example of what can go wrong when government asks to build weaknesses into security systems," said Felten in a blog post.

"Many web sites are vulnerable to this attack, allowing an adversary in the network to spoof or spy on traffic to vulnerable sites."

Felten said that the vulnerability on the NSA site is "not a big national security problem in itself because NSA doesn't distribute state secrets from its public site. But there is an important lesson here about the consequences of crypto policy decisions."

Green said Facebook's site which operates the "like" button was identified as vulnerable but later patched.

Green said the most of the flaws "will soon be patched" but that the flaw is important at a time when the NSA is seeking to maintain access to encrypted software and devices for national security reasons.

"The moral of this story is pretty simple: Encryption backdoors will always turn around and bite you in the ass," he wrote.

번호 제목 글쓴이 날짜 조회 수
40689 Safe Slots Online 3467 MackSterrett625052 2022.01.30 2
40688 Good Slot Online Useful Information 7159 KendrickCoombes 2022.01.30 2
40687 Rolling Cash 5 (5/35) EnriquetaSage165108 2022.01.30 2
40686 'I Do Believe In Myself': Solskjaer Says After Liverpool Thrashing ClaudiaChappell0 2022.01.30 2
40685 Bombillas Led Vela JolieLitchfield9125 2022.01.30 2
40684 김천출장: Shouldn't Be That Troublesome As You Think AdanWertheim06114647 2022.01.30 2
40683 Learn Online Gambling Site Secrets 74619 AdrianneDane625189 2022.01.30 2
40682 Playing Online Gambling Site Tips 59195 Irving56C216321216 2022.01.30 2
40681 Fenster Günstig Online Kaufen XiomaraGist197649272 2022.01.30 2
40680 Understanding Binary Options Trading - Gok News HenryAird27671736 2022.01.30 2
40679 Where Can I Identify A CBD Dispensary Near Me? VHWRosella9228611001 2022.01.30 2
40678 Your IPhone And IPad Have A Hidden Trackpad. Here's How To Unlock It TeriFeierabend907 2022.01.30 2
40677 PS5 Restock Tracker: Amazon Had Consoles And Target Likely To Have A Big Console Drop Soon LeonaDelano322421033 2022.01.30 2
40676 10 Suggestions For Flats DelilahGurley75 2022.01.30 2
40675 Qatar Relaxed As World Fumes VetaGriver35069 2022.01.30 2
40674 Top 5 Digital Marketing Trends To Look For In 2021 DarrelBenn353995 2022.01.30 2
40673 How Slot Machines Work – And Why You Should Think Twice Before Playing Them MarilouBenjamin94019 2022.01.30 2
40672 Are You Ready To Have A Career? Career Suggestions For Everybody! HungCockett685916 2022.01.30 2
40671 The Fit Is Awesome. DottyHeritage982 2022.01.30 2
40670 Have A Pet_ You Won't Be Able To Miss Out On This!... Advice Num 19 From 122 KelseyV9450414873 2022.01.30 2
위로