No. 1 Story

Construction needs cloud flexibility

Australia’s embattled construction sector could benefit from cloud based information systems that can be switched on and off in lockstep with individual projects – with the exception of those organisations based in remote areas like the Kimberleys.

read more

Related Articles

SSL, TLS, vulnerable, publiclydisclosed, attack
Juniper Networks has extended its SSL VPN security to the iPad with the release...
Today's release of the report "In the Crossfire: Critical Infrastructure in the Age of...
A new version of F5's FirePass Controller SSL VPN software is the first of...
A buffer overflow vulnerability in Snort, the popular open-source intrusion detection system for Linux...
It's not a case of the lucky sevens for Cisco - 77 of their...

SSL, TLS vulnerable to publicly-disclosed attack

Business IT - Security

A serious flaw has been discovered in the SSL (Secure Sockets Layer) protocol used to protect data in transit across the Internet. Are your Internet banking transactions at risk?

Security researchers at PhoneFactor have identified a flaw in SSL - not in implementations of SSL, but in the protocol itself.

The flaw makes it possible to execute a man-in-the-middle attack, which involves a third party inserting itself between (eg) the browser and the server to intercept and possibly modify the data flowing across the link without revealing its presence. There is also potential for fraudulently reusing intercepted credentials.

PhoneFactor's Marsh Ray and Steve Dispensa discovered the flaw in August, and privately disclosed it to a vendor working group and representatives of the Internet Engineering Task Force in late September.

The group determined how to address the underlying problem and formulated a set of methods to mitigate the problem.

Since implementation of the agreed plan would take time, PhoneFactor volunteered to delay public disclosure until early 2010. However, SAP's Martin Rex also discovered the vulnerability while examining client certificate authentication by Microsoft's Internet Information Services (IIS) and made it public this week in a message to the mailing list of the IETF's Transport Layer Security (TLS) working group.

(SSL evolved into TLS; the older term is used here are iTWire believes it will be more familiar to most readers. All previously published versions of TLS and SSL are vulnerable.)

CONTINUED