Business IT - Technology for your business

No. 1 Story

Cloud alliance sides with Optus on copyright

OzHub, the Macquarie Telecom-led cloud computing alliance, has come down firmly on the side of Optus over the copyright controversy surrounding Optus TV Now, warning that any moves to change the law "risk branding Australia a global luddite state."

read more

SSL, TLS vulnerable to publicly-disclosed attack

Business IT - Security

Although Rex's scenario was relatively specific, it had enough in common with PhoneFactor's discoveries to lead that company to go public.

All libraries and programs implementing SSL will need to be updated, and it seems that smartcard-based systems as well as the supposedly secure HTTPS connections between browsers and web servers are affected.

Until the problem is fixed, you won't be able to trust the little key in your browser that you thought meant nobody could eavesdrop on your Intenet banking session, for example.

The difficulty with such a fundamental issue is that it requires a co-ordinated response. If updated protocol documents are made public before the implementations are ready, the bad guys have a window of opportunity.

The same situation occurs if one or more developers provide updates before their peers are ready to do the same.

Furthermore, the whole point of a protocol is that standardises the way a particular task is performed. So if one end of the link is fixed and the other still insists on doing things the old way, it is possible that no improvement in security will be achieved.

It is understood that some widely used code has already been patched and testing is underway. But now that word is out, all developers will most likely be pressing ahead to complete the job as soon as possible.

Loading comments ...



- sponsored feature -

The Death of Traditional BI: What’s Next?

How to Make Business Discovery Work for Your Business IP PABX BUYING GUIDE

Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more