메뉴 건너뛰기

XEDITION

Board

Newly Found Online Security Flaw Stems From 1990s

BeatrizLarios71259 2022.05.11 08:33 조회 수 : 1

Newly found online security flaw stems from 1990s

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday.

The flaw dubbed "FREAK" could leave thousands of websites open to attacks if the problem is not patched, according to papers released by French and US researchers.

The flaw was discovered by a team led by Karthikeyan Bhargavan at INRIA in Paris -- the French Institute for Research in Computer Science and Automation -- and disclosure coordinated by Matthew Green, a cryptographer at Johns Hopkins University.

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday ©Thomas Samson (AFP/File)

A research paper said the flaw comes from "a class of deliberately weak export cipher suites... introduced under the pressure of US government agencies to ensure that the NSA would be able to decrypt all foreign encrypted communication."

Green said in a blog post that even some sites maintained by the National Security Agency and FBI appeared to be vulnerable.

"Since the NSA was the organization that demanded export-grade crypto, it's only fitting that they should be the first site affected by this vulnerability," Green said.

Green and other researchers said the flaw stems from US government-imposed standards for encryption in software that was exported -- a short-lived effort to allow the United States to be able to access software exported to unfriendly regimes.

- Part of the software -

Even after it became legal to export strong encryption, the export mode feature was not removed from because some software still depended on it, according to Ed Felten, a Princeton University computer science professor.

"The flaw is significant in itself, but it is also a good example of what can go wrong when government asks to build weaknesses into security systems," said Felten in a blog post.

"Many web sites are vulnerable to this attack, allowing an adversary in the network to spoof or spy on traffic to vulnerable sites."

Felten said that the vulnerability on the NSA site is "not a big national security problem in itself because NSA doesn't distribute state secrets from its public site. But there is an important lesson here about the consequences of crypto policy decisions."

Green said Facebook's site which operates the "like" button was identified as vulnerable but later patched.

Green said the most of the flaws "will soon be patched" but that the flaw is important at a time when the NSA is seeking to maintain access to encrypted software and devices for national security reasons.

"The moral of this story is pretty simple: Encryption backdoors will always turn around and bite you in the ass," he wrote.

번호 제목 글쓴이 날짜 조회 수
21154 WarnerMedia CEO Jason Kilar To Leave His Post Ahead Of Discover Merger MargeneGeorg777659 2022.04.15 2
21153 Best Friends Granddaughter EvieGottshall4408 2022.04.15 2
21152 The Ideal Free Of Charge & Compensated VPNs To Get A British Isles IP Handle AlejandrinaTrommler9 2022.04.15 2
21151 US Seizes $34M In Crypto Tied To Hacked HBO, Netflix, Uber Account Data Sold On Dark Web TrinidadMoritz9 2022.04.15 2
21150 5 Reasons Why Social Media Is Essential For SEO MarianBirtwistle 2022.04.15 2
21149 Uae Exchange Wembley AlfredoLoo1061104 2022.04.15 2
21148 Star Casino To Pay $13m After 'wage Theft' JaredCoulombe2365 2022.04.15 2
21147 Hundreds Of Drug-laced Lollipops Found In NSW Police Raid DarellAzq912550421257 2022.04.15 2
21146 PDF Technology Boosts The Campus Productivity JustineBruni42483 2022.04.15 2
21145 EBay Forecasts Robust Holiday Sales As Online Shopping Drives... JessieA9583446900443 2022.04.15 2
21144 Военный Госпиталь В Китае RuebenGross747006 2022.04.15 2
21143 All You Need To Know About Thumb Sucking MyrtleRadke822844 2022.04.15 2
21142 Pixel 6 Pro Review: Google's Flagship Phone Is A Proper IPhone Rival MaiKohlmeier15707171 2022.04.16 2
21141 The Top Online Uk Casino Web-sites Catherine52749928547 2022.04.16 2
21140 Application Firewall Error HazelCourtney310515 2022.04.16 2
21139 Moment Hit-and-run Driver Crashes Into Pram And Kills 18-day-old Baby ShavonneKez36824289 2022.04.16 2
21138 Don't Make These Mistakes With Cannabis Clinics RuthGaertner764949823 2022.04.16 2
21137 The U.S. Supreme Court And Same Sex Marriage OVDEli731937770343 2022.04.16 2
21136 Whitetail Deer Hunting Outfitters ElizabethBarela025 2022.04.16 2
21135 car Singapore WolfgangP7647438 2022.04.16 2
위로