메뉴 건너뛰기

XEDITION

Board

Newly Found Online Security Flaw Stems From 1990s

BeatrizLarios71259 2022.05.11 08:33 조회 수 : 1

Newly found online security flaw stems from 1990s

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday.

The flaw dubbed "FREAK" could leave thousands of websites open to attacks if the problem is not patched, according to papers released by French and US researchers.

The flaw was discovered by a team led by Karthikeyan Bhargavan at INRIA in Paris -- the French Institute for Research in Computer Science and Automation -- and disclosure coordinated by Matthew Green, a cryptographer at Johns Hopkins University.

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday ©Thomas Samson (AFP/File)

A research paper said the flaw comes from "a class of deliberately weak export cipher suites... introduced under the pressure of US government agencies to ensure that the NSA would be able to decrypt all foreign encrypted communication."

Green said in a blog post that even some sites maintained by the National Security Agency and FBI appeared to be vulnerable.

"Since the NSA was the organization that demanded export-grade crypto, it's only fitting that they should be the first site affected by this vulnerability," Green said.

Green and other researchers said the flaw stems from US government-imposed standards for encryption in software that was exported -- a short-lived effort to allow the United States to be able to access software exported to unfriendly regimes.

- Part of the software -

Even after it became legal to export strong encryption, the export mode feature was not removed from because some software still depended on it, according to Ed Felten, a Princeton University computer science professor.

"The flaw is significant in itself, but it is also a good example of what can go wrong when government asks to build weaknesses into security systems," said Felten in a blog post.

"Many web sites are vulnerable to this attack, allowing an adversary in the network to spoof or spy on traffic to vulnerable sites."

Felten said that the vulnerability on the NSA site is "not a big national security problem in itself because NSA doesn't distribute state secrets from its public site. But there is an important lesson here about the consequences of crypto policy decisions."

Green said Facebook's site which operates the "like" button was identified as vulnerable but later patched.

Green said the most of the flaws "will soon be patched" but that the flaw is important at a time when the NSA is seeking to maintain access to encrypted software and devices for national security reasons.

"The moral of this story is pretty simple: Encryption backdoors will always turn around and bite you in the ass," he wrote.

번호 제목 글쓴이 날짜 조회 수
49869 Cheryl Burke Reveals She Had An Abortion At Just 18 MarianaJunkins076525 2022.11.04 1
49868 Bagaimana Menolong Beliau Game Online Shop Kepada Aplikasi Steam MillieLoar86230613377 2022.11.04 1
49867 Замена Эндопротеза В Клинике Чоботарі BartLinn839061848900 2022.11.04 1
49866 North Warning System NatashaCaban688723 2022.11.04 1
49865 New Step By Step Map For UK VPN TeraLarnach445172 2022.11.04 1
49864 New On The Net Casinos 2022 List Of Major New Gambling Web Pages! Billie877857954858220 2022.11.04 1
49863 Farewell Towards The Atkins Lower Carb Diet ZelmaMatheson093770 2022.11.04 1
49862 Продвижение Сайтов За Рубежом CooperFernando4 2022.11.04 1
49861 Earn From Lotto Send That Initial Scratch . Imagined ByronTulaba6834 2022.11.04 1
49860 PhD Student Investigated For Paper About Him Masturbating To Comics PhilomenaWtg517 2022.11.04 1
49859 How Pressured Bookkeeper Stole $2MILLION From Her Manager In Clever Con APXRamonita3871582 2022.11.04 1
49858 11 Steps On Ways To Get Your Husband To Cover Postnatal Massage At Home EthelKnouse1788 2022.11.04 1
49857 Cynthia Erivo Dazzles At Star-studded Louis Vuitton Show For PFW LaunaHuskey7444 2022.11.04 1
49856 Which Are The Q0 Biggest Lightning Myths Out There? AdelaidaRex4032177 2022.11.04 1
49855 Game Online Detective Paling Baik Untuk Mengomeli Analisa CalebL15710108409 2022.11.03 1
49854 How To Get Unlimited Coins On Apex Legends apexlegandfreecoins 2022.11.03 1
49853 2. سئو چگونه مساله می کند؟ BrandieBeazley70085 2022.11.03 1
49852 slot JonasLin3685391010 2022.11.03 1
49851 Enhance(Increase) Your Lawyer Visa In Three Days WillHurwitz3603 2022.11.03 1
49850 Lg Ke970 Shine - The Simple Phone That Actually Shines AlphonsoPrindle65285 2022.11.03 1
위로