More SSL encryption issues

Researchers have recently uncovered a major security flaw in software created by companies like Google and Apple, leaving many devices vulnerable to hacking attempts, reports HYPERLINK “http://www.washingtonpost.com/blogs/the-switch/wp/2015/03/03/freak-flaw-undermines-security-for-apple-and-google-users-researchers-discover/“The Washington Post. Called “FREAK” (Factoring Attack on RSA-EXPORT Keys), the vulnerability stems from a U.S. government policy that once prevented companies from exporting strong encryption, requiring them to instead create weak “export-grade” products to ship to customers outside of the United States.

These restrictions were lifted more than a decade ago, but the weaker encryption has continued to be used by software companies as a result of the old policy and it has even been built into software in the U.S. The existence of lingering “export-grade” encryption was unnoticed until this year, when researchers found they could force browsers to use lower-grade 512-bit encryption and then crack it.

Hackers could potentially employ the same tactic, cracking weak encryption and then stealing passwords and other information. Researchers also believe the vulnerability could be used to launch attacks on and infiltrate major websites. In testing, the export-grade encryption key was breached in seven hours using computers and more than a quarter of encrypted sites were found to be vulnerable.

“We thought of course people stopped using it,” said Karthikeyan Bhargavan, a researcher at the French computer science lab INRIA whose team initially found the problem during testing of encryption systems.

Nadia Heninger, a University of Pennsylvania cryptographer, said, “This is basically a zombie from the ’90s… I don’t think anybody really realized anybody was still supporting these export suites.”

As pointed out by The Washington Post, the FREAK vulnerability is an example of the problems that can arise when the government gets involved in device security. Government officials have HYPERLINK “http://www.macrumors.com/2014/09/25/rbi-concerned-with-apple-encryption/“recently expressed concern over the privacy features that Apple and Google have been building into their smartphones in response to outrage over secretive government surveillance programs HYPERLINK “http://www.macrumors.com/2013/06/06/intelligence-program-gives-us-government-direct-access-to-customer-data-on-apple-servers/“like PRISM.

FBI Director James Comey has made remarks suggesting Apple and Google should scale back encryption, as government access to electronic devices is necessary in some cases. He has said that it may matter a “great, great deal” that the government be able to infiltrate the device of a kidnapper, criminal, or terrorist.

The researchers who discovered the flaw have notified government sites and major technology companies to fix the issue before it became widely publicized. FBI.gov and Whitehouse.gov have been fixed, and according to Apple spokeswoman Trudy Miller, Apple is preparing a security patch that will be “in place next week for both its computers and its mobile devices.”

 

Article curtesy of Mac rumours

 

This entry was posted in Security Alerts. Bookmark the permalink.

2 Responses to More SSL encryption issues

  1. cracks says:

    Your website content is very effective and help full for people.I understood that you try to clear that concept about this subject.But i also read another content from another website. I think it’s most better full content to your website content.So i suggest you, if you have a time to on your hand you will try to visit this website. http://crackstools.com

  2. Derek Spindle says:

    Hello! Would you mind if I share your blog with my facebook group?There’s a lot of people that I think would really appreciate your content.Please let me know. Thanks

Comments are closed.