메뉴 건너뛰기

XEDITION

Board

Newly Found Online Security Flaw Stems From 1990s

BeatrizLarios71259 2022.05.11 08:33 조회 수 : 1

Newly found online security flaw stems from 1990s

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday.

The flaw dubbed "FREAK" could leave thousands of websites open to attacks if the problem is not patched, according to papers released by French and US researchers.

The flaw was discovered by a team led by Karthikeyan Bhargavan at INRIA in Paris -- the French Institute for Research in Computer Science and Automation -- and disclosure coordinated by Matthew Green, a cryptographer at Johns Hopkins University.

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday ©Thomas Samson (AFP/File)

A research paper said the flaw comes from "a class of deliberately weak export cipher suites... introduced under the pressure of US government agencies to ensure that the NSA would be able to decrypt all foreign encrypted communication."

Green said in a blog post that even some sites maintained by the National Security Agency and FBI appeared to be vulnerable.

"Since the NSA was the organization that demanded export-grade crypto, it's only fitting that they should be the first site affected by this vulnerability," Green said.

Green and other researchers said the flaw stems from US government-imposed standards for encryption in software that was exported -- a short-lived effort to allow the United States to be able to access software exported to unfriendly regimes.

- Part of the software -

Even after it became legal to export strong encryption, the export mode feature was not removed from because some software still depended on it, according to Ed Felten, a Princeton University computer science professor.

"The flaw is significant in itself, but it is also a good example of what can go wrong when government asks to build weaknesses into security systems," said Felten in a blog post.

"Many web sites are vulnerable to this attack, allowing an adversary in the network to spoof or spy on traffic to vulnerable sites."

Felten said that the vulnerability on the NSA site is "not a big national security problem in itself because NSA doesn't distribute state secrets from its public site. But there is an important lesson here about the consequences of crypto policy decisions."

Green said Facebook's site which operates the "like" button was identified as vulnerable but later patched.

Green said the most of the flaws "will soon be patched" but that the flaw is important at a time when the NSA is seeking to maintain access to encrypted software and devices for national security reasons.

"The moral of this story is pretty simple: Encryption backdoors will always turn around and bite you in the ass," he wrote.

번호 제목 글쓴이 날짜 조회 수
122 Seven Magical Mind Tips To Help You Declutter Best Cryptocurrency Exchange BernieVerge27579579 2021.08.03 1
121 This Brief Article Teaches You The Ins And Outs Of Crypto Mining Systems And What You Should Do Today KerstinCompton0409 2022.01.04 1
120 Give Me Ten Minutes, I'll Give You The Truth About Coin Prices LindsayCarnarvon 2022.01.24 1
119 What Does The Most Recent ECash(XEC) Worth Prediction Look Like? Ecash 2022.03.08 1
118 Server Rental For Crypto Andrew46D0066983238 2022.04.12 1
117 25 Fiduciary Currencies Suitable With The Company's Platform FelipaLiles3296 2022.05.19 1
116 What Are The Reasons For Development In Income Of AI EarlenePenman0475116 2022.05.19 1
115 How To Use Social Proof In Your Marketing? RoxanaHaller87608 2022.06.14 1
114 Do Not Get As Well Excited. You Will Not Be Done With Ethanim ThedaMcDavid65897 2022.06.16 1
113 I Switched From Android To IPhone And Found Out What My Friends Really Think EldenHolley157392240 2022.07.03 1
112 Ohio Man Charged For Laundering $300 Million By Way Of Bitcoin 'mixer' NolaBaskett977695976 2022.07.08 1
111 Bitcoin Miners Create Invalid Forex After A Botched Upgrade RosalindWinston882 2022.07.10 1
110 'Demon Quake' On Mars: National Aeronautics And Space Administration Insight Lander Records Cherry Satellite Doing An Epic Shimmy AlvaroGreenfield 2022.07.15 1
109 Never Lose Your Make Money Money Take Money Money Again LeanneStuber762 2022.10.13 1
108 How Crypto Trading Signals Help Novice Traders To Place Successful Trades? MacDetwiler98238652 2023.01.14 1
107 Exactly Why Are News Journals So Well Liked? TPVPenni7913324 2023.02.22 1
106 Musings On Markets EleanoreCvm087858 2023.04.08 1
105 What's The Best Crypto Forum For Talking About Cryptocurrency Coins JacquelynSkalski1878 2023.06.11 1
104 Ten The Explanation Why Having An Excellent Crypto Will Not Be Enough JJFElyse4536212 2023.11.30 1
103 The Unexposed Secret Of Cryptocurrency Exchange Bitcoin UlyssesMora579270797 2024.02.06 1
위로