메뉴 건너뛰기

XEDITION

Board

Newly Found Online Security Flaw Stems From 1990s

BeatrizLarios71259 2022.05.11 08:33 조회 수 : 1

Newly found online security flaw stems from 1990s

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday.

The flaw dubbed "FREAK" could leave thousands of websites open to attacks if the problem is not patched, according to papers released by French and US researchers.

The flaw was discovered by a team led by Karthikeyan Bhargavan at INRIA in Paris -- the French Institute for Research in Computer Science and Automation -- and disclosure coordinated by Matthew Green, a cryptographer at Johns Hopkins University.

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday ©Thomas Samson (AFP/File)

A research paper said the flaw comes from "a class of deliberately weak export cipher suites... introduced under the pressure of US government agencies to ensure that the NSA would be able to decrypt all foreign encrypted communication."

Green said in a blog post that even some sites maintained by the National Security Agency and FBI appeared to be vulnerable.

"Since the NSA was the organization that demanded export-grade crypto, it's only fitting that they should be the first site affected by this vulnerability," Green said.

Green and other researchers said the flaw stems from US government-imposed standards for encryption in software that was exported -- a short-lived effort to allow the United States to be able to access software exported to unfriendly regimes.

- Part of the software -

Even after it became legal to export strong encryption, the export mode feature was not removed from because some software still depended on it, according to Ed Felten, a Princeton University computer science professor.

"The flaw is significant in itself, but it is also a good example of what can go wrong when government asks to build weaknesses into security systems," said Felten in a blog post.

"Many web sites are vulnerable to this attack, allowing an adversary in the network to spoof or spy on traffic to vulnerable sites."

Felten said that the vulnerability on the NSA site is "not a big national security problem in itself because NSA doesn't distribute state secrets from its public site. But there is an important lesson here about the consequences of crypto policy decisions."

Green said Facebook's site which operates the "like" button was identified as vulnerable but later patched.

Green said the most of the flaws "will soon be patched" but that the flaw is important at a time when the NSA is seeking to maintain access to encrypted software and devices for national security reasons.

"The moral of this story is pretty simple: Encryption backdoors will always turn around and bite you in the ass," he wrote.

번호 제목 글쓴이 날짜 조회 수
18207 เพิ่มเติม TeraD653542971096 2022.12.01 2
18206 Psycho Therapist Vs Psychoanalyst - Which One Do I Require? LeiaHeflin69184 2022.12.01 0
18205 What Is The Myofascial Release Technique? JeannaV99253977588416 2022.12.01 1
18204 Apa Surplus Dari Judi Mesin Slots Daring? Annie08J18660303925 2022.12.01 0
18203 Macau Shuts Most Businesses Amid COVID Outbreak, Casinos Stay Open Clarita1312836613574 2022.12.01 1
18202 Bills Sign WR Crowder, RB Duke Johnson To 1-year Contracts BradleyVmq1685166036 2022.12.01 0
18201 Some Great Tips On How To Save Money Part 2 Fernando47E1431343554 2022.12.01 1
18200 Is It Time To Talk More About Buy An A Apt AmeeToussaint3594877 2022.12.02 0
18199 Transmissions From A Dying World Most Disturbing Issues On The Deep Web: PenneyYarnold500 2022.12.02 0
18198 Things To Take Into Consideration When Choosing To Play JILIBET Online Casino GabrielleRech4888 2022.12.02 0
18197 Trik Menunjuk Sabung Ayam Online Dengan Cepat Candy632245548084034 2022.12.02 0
18196 نیکو سازش پیج رنک تیره است! BradyBeeston264 2022.12.02 0
18195 The Particulars Of Charge Bitcoin Card MarciaRowell6438 2022.12.02 1
18194 Why My Influencer Marketing Is Healthier Than Yours LilianTolmie99551235 2022.12.02 0
18193 Keuntungan Main Di Slots Online Teranyar JameBoren6852997735 2022.12.02 0
18192 การแสวงหาผู้ให้บริการคาสินออนไลน์ ที่ดีที่สุด EllenLavender69 2022.12.02 1
18191 Handbags, Purses And Toolboxes, Oh My! CarmellaLopresti70 2022.12.02 0
18190 Lottery Winning Number - Know Probably The Most Combination For Lucky Winning Numbers BobWehner1413327544 2022.12.02 0
18189 Seo Tool Which We Need To Rank Our Website NathanScarberry5306 2022.12.02 0
18188 What Are The Best Slots On Mega88 Online Casino? BurtonWillson298623 2022.12.02 0
위로