메뉴 건너뛰기

XEDITION

Board

Newly Found Online Security Flaw Stems From 1990s

BeatrizLarios71259 2022.05.11 08:33 조회 수 : 1

Newly found online security flaw stems from 1990s

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday.

The flaw dubbed "FREAK" could leave thousands of websites open to attacks if the problem is not patched, according to papers released by French and US researchers.

The flaw was discovered by a team led by Karthikeyan Bhargavan at INRIA in Paris -- the French Institute for Research in Computer Science and Automation -- and disclosure coordinated by Matthew Green, a cryptographer at Johns Hopkins University.

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday ©Thomas Samson (AFP/File)

A research paper said the flaw comes from "a class of deliberately weak export cipher suites... introduced under the pressure of US government agencies to ensure that the NSA would be able to decrypt all foreign encrypted communication."

Green said in a blog post that even some sites maintained by the National Security Agency and FBI appeared to be vulnerable.

"Since the NSA was the organization that demanded export-grade crypto, it's only fitting that they should be the first site affected by this vulnerability," Green said.

Green and other researchers said the flaw stems from US government-imposed standards for encryption in software that was exported -- a short-lived effort to allow the United States to be able to access software exported to unfriendly regimes.

- Part of the software -

Even after it became legal to export strong encryption, the export mode feature was not removed from because some software still depended on it, according to Ed Felten, a Princeton University computer science professor.

"The flaw is significant in itself, but it is also a good example of what can go wrong when government asks to build weaknesses into security systems," said Felten in a blog post.

"Many web sites are vulnerable to this attack, allowing an adversary in the network to spoof or spy on traffic to vulnerable sites."

Felten said that the vulnerability on the NSA site is "not a big national security problem in itself because NSA doesn't distribute state secrets from its public site. But there is an important lesson here about the consequences of crypto policy decisions."

Green said Facebook's site which operates the "like" button was identified as vulnerable but later patched.

Green said the most of the flaws "will soon be patched" but that the flaw is important at a time when the NSA is seeking to maintain access to encrypted software and devices for national security reasons.

"The moral of this story is pretty simple: Encryption backdoors will always turn around and bite you in the ass," he wrote.

번호 제목 글쓴이 날짜 조회 수
49443 Brazil's Food Retailer GPA Sees Online Sales Rising Fivefold In 4-5... ChristiDial709479 2022.10.01 1
49442 How To Find The Best Options Tutorial PaulHobler71555757 2022.10.01 1
49441 Remède De La Repousse Des Cheveux À Montréal KristaZ8540623957078 2022.10.01 1
49440 Winner55 KennithCarmichael 2022.10.01 1
49439 Top Male Enhancers And Porn Star Penis Growth And Penis Cosmetic Surgery EvaleenChristmas 2022.10.01 1
49438 PusatFreebet : Kumpulan Slot Freebet Terbaru Dan Bet Gratis Terpercaya BrookBenham4486 2022.10.01 1
49437 slot MarioBainton408480 2022.10.01 1
49436 Google LouisByp55108070496 2022.10.01 1
49435 Massage And Love - How They Are The Same CaitlynGiltner68 2022.10.01 1
49434 Tennis-Give Women Prime Time Slots, Says King, Backing Mauresmo To... ClaudiaNorthrup3729 2022.10.01 1
49433 Delphi Adventure Centre AveryKau5805162 2022.10.01 1
49432 The Best Soccer Players Of All Time SelmaDorron2104364 2022.10.01 1
49431 Un Puntatore Laser Gattopuò Fornire Molti Vantaggi NathanielZnz860651 2022.10.01 1
49430 What Are Auto Likes? ErickaReed45379 2022.10.01 1
49429 Real Estate And What You Need To Know On Buying It RGTJake94639598599 2022.10.01 1
49428 Thi Học Kỳ Theo Hình Thức Trực Tuyến Có đảm Bảo Khách Quan, Công Bằng? HalleyLewers65960604 2022.10.01 1
49427 Six Fundamentals For Writing An Excellent Case Study EstebanNeel439157 2022.10.01 1
49426 Watsu Remedy Rusty3786022101 2022.10.01 1
49425 These 10 Hacks Will Make You(r) Read Hentai For Free (Look) Like A Professional hentaisister7vq 2022.10.01 1
49424 My First Visit To The Island Of Spinalonga Seems Like It Was Yesterday HJIClarissa51134353 2022.10.01 1
위로