메뉴 건너뛰기

XEDITION

Board

Newly Found Online Security Flaw Stems From 1990s

BeatrizLarios71259 2022.05.11 08:33 조회 수 : 0

Newly found online security flaw stems from 1990s

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday.

The flaw dubbed "FREAK" could leave thousands of websites open to attacks if the problem is not patched, according to papers released by French and US researchers.

The flaw was discovered by a team led by Karthikeyan Bhargavan at INRIA in Paris -- the French Institute for Research in Computer Science and Automation -- and disclosure coordinated by Matthew Green, a cryptographer at Johns Hopkins University.

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday ©Thomas Samson (AFP/File)

A research paper said the flaw comes from "a class of deliberately weak export cipher suites... introduced under the pressure of US government agencies to ensure that the NSA would be able to decrypt all foreign encrypted communication."

Green said in a blog post that even some sites maintained by the National Security Agency and FBI appeared to be vulnerable.

"Since the NSA was the organization that demanded export-grade crypto, it's only fitting that they should be the first site affected by this vulnerability," Green said.

Green and other researchers said the flaw stems from US government-imposed standards for encryption in software that was exported -- a short-lived effort to allow the United States to be able to access software exported to unfriendly regimes.

- Part of the software -

Even after it became legal to export strong encryption, the export mode feature was not removed from because some software still depended on it, according to Ed Felten, a Princeton University computer science professor.

"The flaw is significant in itself, but it is also a good example of what can go wrong when government asks to build weaknesses into security systems," said Felten in a blog post.

"Many web sites are vulnerable to this attack, allowing an adversary in the network to spoof or spy on traffic to vulnerable sites."

Felten said that the vulnerability on the NSA site is "not a big national security problem in itself because NSA doesn't distribute state secrets from its public site. But there is an important lesson here about the consequences of crypto policy decisions."

Green said Facebook's site which operates the "like" button was identified as vulnerable but later patched.

Green said the most of the flaws "will soon be patched" but that the flaw is important at a time when the NSA is seeking to maintain access to encrypted software and devices for national security reasons.

"The moral of this story is pretty simple: Encryption backdoors will always turn around and bite you in the ass," he wrote.

번호 제목 글쓴이 날짜 조회 수
20288 Fitur Online Poker Android Terbaik Yang Harus Dikenal LucienneCrumley22 2022.07.29 0
20287 Bocoran Penting Rekomendasi Pro Dalam Bermain Poker Online LucienneCrumley22 2022.07.29 0
20286 TIPS BERSEPEDA DI MUSIM PENGHUJAN ALA DUNIA SEPEDA TarahChambless81 2022.07.29 0
20285 Starling Marte's Walk-off Single Puts Mets Past Yanks OVYJai54413178802210 2022.07.29 0
20284 Olympics-Alpine Skiing-Cold Food Riles Germany Coach, U.S. Bring... ChelseaTrevascus 2022.07.29 0
20283 Every Cool Feature We Found In The IOS 16 Public Beta Ross33C00262381 2022.07.29 0
20282 Play Online Slots, PG Slot, How Good Is PG Slot, A Big Website? JudeVan72953919730 2022.07.29 0
20281 Perks Of Social Media Advertising For Small Businesses? LesSpringer504217622 2022.07.29 0
20280 Czym Są Portale Internetowe ? www.xmc.plfdpym 2022.07.29 0
20279 พวกเราเป็นผู้ให้บริการ BETFLIX เว็บสล็อต SherrillGilson68921 2022.07.29 0
20278 2010 Detroit Lions - Nfl Predictions, Odds And Betting Picks JeseniaVonwiller533 2022.07.29 0
20277 U.S. Abortion Groups See Support Spike After Roe V Wade Overturned ReneeBaron570533745 2022.07.29 0
20276 Nfl Betting Odds Explained DianaBarry42936 2022.07.29 0
20275 Try Slots Roma, Slots XO , Fun Slot Games A Game That Has Made Money For Thousands Of Players BarbaraLedet45053961 2022.07.29 0
20274 Treasury Wine Estates To Debut Penfolds French Origin Wines SheilaMactier972 2022.07.29 0
20273 At Least Two Killed As Security Forces Clash In Libya's Tripoli StormyNesmith4202731 2022.07.29 0
20272 If You Liked Stranger Things, You'll Love These 14 Movies JustinWisdom5918196 2022.07.29 0
20271 DISSERTATIONS Money Experiment AmadoH534502418 2022.07.29 0
20270 Slot88ku Web JUDI SLOT ONLINE DEPOSIT SHOPEEPAY OVO GOPAY DANA LINKAJA QRIS TERLENGKAP ChristalProud7172162 2022.07.29 0
20269 see Here Now EvaEhmann135947365 2022.07.30 0
위로