+ Reply to Thread
Results 1 to 13 of 13
  1. #1
    ΜΟΛΩΝ ΛΑΒΕ no1_vern's Avatar
    Join Date
    Apr 2002
    Location
    Albany, Ga.
    Posts
    18,499

    Thumbs down SSL hacked - millions of sites at risk.

     
    Hackers break SSL encryption used by millions of sites - The Register

    Beware of BEAST decrypting secret PayPal cookies

    By Dan Goodin

    Posted in ID, 19th September 2011 21:10 GMT

    The vulnerability resides in versions 1.0 and earlier of TLS, or transport layer security, the successor to the secure sockets layer technology that serves as the internet's foundation of trust. Although versions 1.1 and 1.2 of TLS aren't susceptible, they remain almost entirely unsupported in browsers and websites alike, making encrypted transactions on PayPal, GMail, and just about every other website vulnerable to eavesdropping by hackers who are able to control the connection between the end user and the website he's visiting.
    Its ONLY a "proof of concept" exercise for now, how many hours before its in the wild is anyones guess.
    They say technology slows down for no one. I know it outruns my wallet. I figure its because my wallet isn't light enough yet.

    TechIMO Folding@home Team #111 - Crunching for the cure!
    dulce bellum inexpertis

  2. #2
    Banned
    Join Date
    Feb 2009
    Location
    KFNL FS2004
    Posts
    11,886
    Blog Entries
    1
    I just new it could be done.

    But see now here's the flaw.

    “BEAST is like a cryptographic Trojan horse – an attacker slips a bit of JavaScript into your browser, and the JavaScript collaborates with a network sniffer to undermine your HTTPS connection,”
    I run Noscript, so lets see if this could work on my end. HEHE.
    Last edited by Taxmancometh; September 21st, 2011 at 01:08 PM.

  3. #3
    ΜΟΛΩΝ ΛΑΒΕ no1_vern's Avatar
    Join Date
    Apr 2002
    Location
    Albany, Ga.
    Posts
    18,499
    I use NoScript myself, it is a good piece of software. How many of the hundreds of millions of 'netizens do you think actually use it?
    They say technology slows down for no one. I know it outruns my wallet. I figure its because my wallet isn't light enough yet.

    TechIMO Folding@home Team #111 - Crunching for the cure!
    dulce bellum inexpertis

  4. #4
    Banned
    Join Date
    Feb 2009
    Location
    KFNL FS2004
    Posts
    11,886
    Blog Entries
    1

  5. #5
    Goverment property now GroundZero3's Avatar
    Join Date
    Oct 2001
    Location
    NOVA
    Posts
    33,798
    Blog Entries
    46
    Im waiting for them to demo it, would be interesting to see how well it works out in the wild.

  6. #6
    Ultimate Member
    Join Date
    Feb 2008
    Posts
    1,671
    People who do this REALLY SUCK!!!!!!!

    The world is full of so much evil its not funny....

    NOTHING IS SAFE FROM THESE SCUMBAGS

  7. #7
    Banned
    Join Date
    Feb 2009
    Location
    KFNL FS2004
    Posts
    11,886
    Blog Entries
    1
    That's why you stay ahead of the game. Use Noscript and the exploit won't happen. I bet the author of Noscript will update the addon just for this.

  8. #8
    Goverment property now GroundZero3's Avatar
    Join Date
    Oct 2001
    Location
    NOVA
    Posts
    33,798
    Blog Entries
    46
    Quote Originally Posted by Dude111 View Post
    People who do this REALLY SUCK!!!!!!!

    The world is full of so much evil its not funny....

    NOTHING IS SAFE FROM THESE SCUMBAGS
    You think this is really considered evil? I would give that label to murders, rapist, burglers, and people who prey on little kids that title.

    Its just the internet Dude, dont take it so seriously. Plus if you are still running windows 98 you have bigger things to worry about security wise

  9. #9
    ΜΟΛΩΝ ΛΑΒΕ no1_vern's Avatar
    Join Date
    Apr 2002
    Location
    Albany, Ga.
    Posts
    18,499
    World takes notice as SSL-chewing BEAST is unleashed β€’ The Register
    World takes notice as SSL-chewing BEAST is unleashed


    Google, Microsoft, Mozilla patch cracks in net's foundation of trust

    By Dan Goodin in San Francisco • Get more from this author

    SNIP

    With the decrypting of a protected PayPal browser cookie at a security conference Friday, it became official: the internet's foundation of trust has suffered yet another serious fracture that will require the attention of the industry's best minds.

    Within hours of the demonstration by researchers Juliano Rizzo and Thai Duong, Google researcher Adam Langley signaled his growing acceptance that secure sockets layer, the decade-old cryptographic standard that protects web addresses using the https prefix, was susceptible to an attack that previously was considered impractical. The result: by tampering with with an encryption algorithm's CBC – cipher block chaining – mode, hackers could secretly decrypt portions of the encrypted traffic.
    Firefox devs mull dumping Java to stop BEAST attacks β€’ The Register
    Firefox developers searching for a way to protect users against a new attack that decrypts sensitive web traffic are seriously considering an update that stops the open-source browser from working with Oracle's Java software framework.
    They say technology slows down for no one. I know it outruns my wallet. I figure its because my wallet isn't light enough yet.

    TechIMO Folding@home Team #111 - Crunching for the cure!
    dulce bellum inexpertis

  10. #10
    Banned
    Join Date
    Feb 2009
    Location
    KFNL FS2004
    Posts
    11,886
    Blog Entries
    1
    My votes for Noscript again. Plus I use an addon called quickjava which allows me to keep Java off unless I need it for a particular website.

  11. #11
    Ultimate Member
    Join Date
    Feb 2008
    Posts
    1,671
    Quote Originally Posted by GroundZero3
    You think this is really considered evil? I would give that label to murders, rapist, burglers, and people who prey on little kids that title.
    Well why do they try to hurt people buddy??

    People they dont even know,what have they done to them??

    Its just so mean all the bad things people do to others online (Virus's,scams,etc)

  12. #12
    Goverment property now GroundZero3's Avatar
    Join Date
    Oct 2001
    Location
    NOVA
    Posts
    33,798
    Blog Entries
    46
    Dude if you take the internet too seriously you will never make it out alive

  13. #13
    Ultimate Member
    Join Date
    Feb 2008
    Posts
    1,671
    Yea i guess thats true!!

    I consider everyone to be a friend and thats sadly not the case..... THE INTERNET DEPICTS REAL LIFE

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. $310+ Millions
    By no1_vern in forum IMO Community
    Replies: 16
    Last Post: November 16th, 2005, 05:56 PM
  2. There's millions to be made!
    By tony_j15 in forum IMO Community
    Replies: 1
    Last Post: July 5th, 2005, 09:28 PM
  3. millions of browsers
    By AztekZoul in forum Security and Privacy Issues
    Replies: 7
    Last Post: September 26th, 2004, 10:11 AM
  4. millions of gallons of oil
    By Sweet in forum IMO Community
    Replies: 9
    Last Post: November 21st, 2002, 07:45 AM
  5. XP Pro can't connect to SSL sites?
    By Nighthawk in forum Technical Support
    Replies: 3
    Last Post: December 14th, 2001, 07:08 PM

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Recommended Sites: ResellerRatings Store Reviews