Stephen Withers
Friday, 06 November 2009 04:15
Business IT -
Security
Page 1 of 2
A serious flaw has been discovered in the SSL (Secure Sockets Layer) protocol used to protect data in transit across the Internet. Are your Internet banking transactions at risk?
Security researchers at PhoneFactor have identified a flaw in SSL - not in implementations of SSL, but in the protocol itself.
The flaw makes it possible to execute a man-in-the-middle attack, which involves a third party inserting itself between (eg) the browser and the server to intercept and possibly modify the data flowing across the link without revealing its presence. There is also potential for fraudulently reusing intercepted credentials.
PhoneFactor's Marsh Ray and Steve Dispensa discovered the flaw in August, and privately disclosed it to a vendor working group and representatives of the Internet Engineering Task Force in late September.
The group determined how to address the underlying problem and formulated a set of methods to mitigate the problem.
Since implementation of the agreed plan would take time, PhoneFactor volunteered to delay public disclosure until early 2010. However, SAP's Martin Rex also discovered the vulnerability while examining client certificate authentication by Microsoft's Internet Information Services (IIS) and made it public this week in a message to the mailing list of the IETF's Transport Layer Security (TLS) working group.
(SSL evolved into TLS; the older term is used here are iTWire believes it will be more familiar to most readers. All previously published versions of TLS and SSL are vulnerable.)
CONTINUED