메뉴 건너뛰기

XEDITION

Board

Newly Found Online Security Flaw Stems From 1990s

BeatrizLarios71259 2022.05.11 08:33 조회 수 : 1

Newly found online security flaw stems from 1990s

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday.

The flaw dubbed "FREAK" could leave thousands of websites open to attacks if the problem is not patched, according to papers released by French and US researchers.

The flaw was discovered by a team led by Karthikeyan Bhargavan at INRIA in Paris -- the French Institute for Research in Computer Science and Automation -- and disclosure coordinated by Matthew Green, a cryptographer at Johns Hopkins University.

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday ©Thomas Samson (AFP/File)

A research paper said the flaw comes from "a class of deliberately weak export cipher suites... introduced under the pressure of US government agencies to ensure that the NSA would be able to decrypt all foreign encrypted communication."

Green said in a blog post that even some sites maintained by the National Security Agency and FBI appeared to be vulnerable.

"Since the NSA was the organization that demanded export-grade crypto, it's only fitting that they should be the first site affected by this vulnerability," Green said.

Green and other researchers said the flaw stems from US government-imposed standards for encryption in software that was exported -- a short-lived effort to allow the United States to be able to access software exported to unfriendly regimes.

- Part of the software -

Even after it became legal to export strong encryption, the export mode feature was not removed from because some software still depended on it, according to Ed Felten, a Princeton University computer science professor.

"The flaw is significant in itself, but it is also a good example of what can go wrong when government asks to build weaknesses into security systems," said Felten in a blog post.

"Many web sites are vulnerable to this attack, allowing an adversary in the network to spoof or spy on traffic to vulnerable sites."

Felten said that the vulnerability on the NSA site is "not a big national security problem in itself because NSA doesn't distribute state secrets from its public site. But there is an important lesson here about the consequences of crypto policy decisions."

Green said Facebook's site which operates the "like" button was identified as vulnerable but later patched.

Green said the most of the flaws "will soon be patched" but that the flaw is important at a time when the NSA is seeking to maintain access to encrypted software and devices for national security reasons.

"The moral of this story is pretty simple: Encryption backdoors will always turn around and bite you in the ass," he wrote.

번호 제목 글쓴이 날짜 조회 수
56953 Ten Issues To Do Immediately About Kawaii Clothes Unisex ZacheryLai2740756 2022.04.23 2
56952 Brazilians Slip Up In Move For Banana Firm Chiquita HopeRehfisch580 2022.04.23 2
56951 Lisa Clark Flashes Her Underwear In A See-through Leopard-print Dress HopeRehfisch580 2022.04.23 4
56950 Lisa Clark Flashes Her Underwear In A See-through Leopard-print Dress HopeRehfisch580 2022.04.23 1
56949 Forex Binary Option Pocket Option Review AntjeValadez296061 2022.04.23 1
56948 Why Are Apartments In Sarjapur Road Buyers First Choice? Tory43L58743089504 2022.04.23 3
56947 Beberapa Cara Taruhan Slot Online Yang Membawa Kerugian ZFGNoemi90910222241 2022.04.23 2
56946 Best Portable Power Stations For 2021 AleidaWtr319974966413 2022.04.23 2
56945 Google SEO Works Wonders In Digital Marketing DeanneHurlburt51526 2022.04.23 1
56944 Whatever You Need To Know About Online Gambling JerriEnos88013913 2022.04.23 7
56943 Web Poker Online Uang Orisinil Terpercaya LiliaRousseau5383303 2022.04.23 3
56942 Gonna University? Read This Report Now! KurtisHead54164022 2022.04.23 2
56941 Betonline Ag Sportsbook Assessment 2021 LouannMajeski99807 2022.04.23 10
56940 PG SLOT ONLINE SLOTS LaurieCallaway191 2022.04.23 4
56939 A Video From 'Instagram Famous' Baker Eloise Head Showing Viewers How To Make Peanut Butter M&M Brownies From Five Ingredients Has Gone Viral On Social Media WandaParer8260975415 2022.04.23 1
56938 No. 8 Houston Stresses Defense Against South Florida DorthyBourke333 2022.04.23 2
56937 The Place Will Laptop Repair Be 6 Months From Now? Shanon23B2836734473 2022.04.23 1
56936 Drift Boss Game xvideosgameuioy 2022.04.23 2
56935 Museums Of Nottingham DLEMarcia55945732 2022.04.23 1
56934 55666 Bong88 Com - Liên Kết Chính Thức Mới Nhất LidiaVenuti688910 2022.04.23 1
위로