SSL 3.0 vulnerability discovered

Started by Corrine, October 15, 2014, 09:18:53 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Corrine

QuoteA security vulnerability in SSL 3.0 has been uncovered by Bodo Möller and two other Google employees that attackers can exploit to calculate the plaintext of secure connections.

SSL 3.0 is an old protocol and most Internet servers use the newer  TLS 1.0, TLS 1.1 or TLS 1.2 protocols instead. Client and server usually  agree to use the latest protocol version during connections during  protocol handshake but since TLS is backwards compatible with SSL 3.0,  it can happen that SSL 3.0 is being used instead.

During the first handshake attempt the highest supported protocol  version is offered but if this handshake fails, earlier protocol  versions are offered instead.
An attacker controlling the network between the client and server  could interfere with the handshake attempt so that SSL 3.0 is used  instead of TLS.

Instructions are available at the source on how to protect your web browser.  See SSL 3.0 vulnerability discovered. Find out how to protect yourself.  Note, however, that the link to test the Protocols includes the caveat, "This test reliably detects only the highest supported protocol."  Thus, it reliably detects TLS 1.2, but will not reliably detect if SSL3 is disabled.  https://www.ssllabs.com/ssltest/viewMyClient.html


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Corrine



Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Digerati

I have disabled 3.0 in my IE with no problems noted - yet.
Bill (AFE7Ret)
Freedom is NOT Free!
2007 - 2018

winchester73

Speak softly, but carry a big Winchester ... Winchester Arms Collectors Association member

Digerati

Bill (AFE7Ret)
Freedom is NOT Free!
2007 - 2018

siljaline

Enable the MS FixIt available here:
https://support.microsoft.com/kb/3009008

FAQ - you generally don't have to undo them as next Patch Tuesday.

siljaline
MVPS Hosts . MBAM . Why ESET

JDBush61

Do folks running Safari on a Mac need to be concerned with this?

I ran the above test(?) [Windows 7, Pale Moon] using the link that Corrine provided and everything seems to be OK.
Is it still necessary to run the MS FixIt?
"In an age when mass society has rendered obsolete the qualities of individual courage and independent thought, the oceans of the world still remain, vast and uncluttered, beautiful but unforgiving, awaiting those who will not submit. Their voyages are not an escape, but a fulfillment."

~ THE SLOCUM SOCIETY ~

siljaline

Irrespective of Browser choice - if running a Windows O/S, you need the FixIt in place, ASAP. 
siljaline
MVPS Hosts . MBAM . Why ESET

siljaline

siljaline
MVPS Hosts . MBAM . Why ESET

JDBush61

Quote from: siljaline on November 06, 2014, 03:39:21 AM
Irrespective of Browser choice - if running a Windows O/S, you need the FixIt in place, ASAP.

Thanks. Now fixed.
"In an age when mass society has rendered obsolete the qualities of individual courage and independent thought, the oceans of the world still remain, vast and uncluttered, beautiful but unforgiving, awaiting those who will not submit. Their voyages are not an escape, but a fulfillment."

~ THE SLOCUM SOCIETY ~

siljaline

Most welcome. Leave the MS FixIt in-place until MS tells us otherwise.

siljaline
MVPS Hosts . MBAM . Why ESET

Lost.

You have to under stand what is going in  a encryption vulnerability.

When you go to buy something on-line your connection should be encrypted

If the site is malware infected it can tell your browser to use the lowest encryption say SSl 3

which has been hacked, So the malware infecter will get your credit card info.

If you have an update browser the lowest encrypted it uses will not have been hacked.

This can cause a compatibility problem if a site uses only hacked encryption.

So it does not matter if you run windows,apple,or Linux.
Choose Kindness and Laugh Often