메뉴 건너뛰기

XEDITION

Board

Newly Found Online Security Flaw Stems From 1990s

BeatrizLarios71259 2022.05.11 08:33 조회 수 : 4

Newly found online security flaw stems from 1990s

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday.

The flaw dubbed "FREAK" could leave thousands of websites open to attacks if the problem is not patched, according to papers released by French and US researchers.

The flaw was discovered by a team led by Karthikeyan Bhargavan at INRIA in Paris -- the French Institute for Research in Computer Science and Automation -- and disclosure coordinated by Matthew Green, a cryptographer at Johns Hopkins University.

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday ©Thomas Samson (AFP/File)

A research paper said the flaw comes from "a class of deliberately weak export cipher suites... introduced under the pressure of US government agencies to ensure that the NSA would be able to decrypt all foreign encrypted communication."

Green said in a blog post that even some sites maintained by the National Security Agency and FBI appeared to be vulnerable.

"Since the NSA was the organization that demanded export-grade crypto, it's only fitting that they should be the first site affected by this vulnerability," Green said.

Green and other researchers said the flaw stems from US government-imposed standards for encryption in software that was exported -- a short-lived effort to allow the United States to be able to access software exported to unfriendly regimes.

- Part of the software -

Even after it became legal to export strong encryption, the export mode feature was not removed from because some software still depended on it, according to Ed Felten, a Princeton University computer science professor.

"The flaw is significant in itself, but it is also a good example of what can go wrong when government asks to build weaknesses into security systems," said Felten in a blog post.

"Many web sites are vulnerable to this attack, allowing an adversary in the network to spoof or spy on traffic to vulnerable sites."

Felten said that the vulnerability on the NSA site is "not a big national security problem in itself because NSA doesn't distribute state secrets from its public site. But there is an important lesson here about the consequences of crypto policy decisions."

Green said Facebook's site which operates the "like" button was identified as vulnerable but later patched.

Green said the most of the flaws "will soon be patched" but that the flaw is important at a time when the NSA is seeking to maintain access to encrypted software and devices for national security reasons.

"The moral of this story is pretty simple: Encryption backdoors will always turn around and bite you in the ass," he wrote.

번호 제목 글쓴이 날짜 조회 수
40211 Direct Web Slots Or Online Slots (slot Online) That Are Becoming Very Popular Right Now. TereseVey060252 2022.05.07 2
40210 Escort Jailed For Over Five Years After Conning 'sugar Daddy' Of £2.5m LorriRodrigues920 2022.05.07 2
40209 WeatherBug- Your Safety Companion During Lightning And Storms TresaBorowski039032 2022.05.07 2
40208 Four Tips For Using Veterinary Clinics Ulan To Leave Your Competition In The Dust CecileBly611600026 2022.05.07 2
40207 Opting For Inventory Choices TangelaGraves92530 2022.05.07 2
40206 Wahl Eines Laserzeigers Stark Olga024125541105 2022.05.07 2
40205 If You're Looking For A Baking Project To Get Stuck Into Over MeganMortensen62 2022.05.07 2
40204 2018 Toyota Tacoma Problems AmieFlockhart76096 2022.05.07 2
40203 Be Confident Within A Job Interview Don't Create Logic LauriStull569076276 2022.05.07 2
40202 The Secret Background People Migration Attorney ErnestIrby53065427861 2022.05.07 2
40201 QUENTIN LETTS Reviews Foxfinder At The Ambassadors Theatre LucyWeber73339800 2022.05.07 2
40200 Most Artistically Friends Granddaughter KeiraRickett06545 2022.05.07 2
40199 Choosing The Best Weight Gain Program RosieSpruill512077 2022.05.07 2
40198 Blue Pit Bull Pictures: Photos Of My APBT CesarFay78961080828 2022.05.07 2
40197 Elegir Un Poderoso Puntero Láser KristinFaber3325 2022.05.07 2
40196 What Niche Internet Marketing Just Isn't Internet Marketing Compared To. Internet Marketing Niche ToshaDial23228339472 2022.05.07 2
40195 4 Lessons About Israel Vacation Policy You Want To Be Taught Earlier Than You Hit 40 Lane04K34923653 2022.05.07 2
40194 6 ความลับสำคัญที่คุณไม่รู้เกี่ยวกับbetflix CaridadBoling93775 2022.05.07 2
40193 Top Khách Sạn Dulichdau.com Eileen90052947051 2022.05.07 2
40192 Cool N Lite Auto365 KlaudiaJlb62213589 2022.05.07 2
위로