iTnews
  • Home
  • News
  • Technology
  • Security

SSL flaw prompts security scramble

By Shaun Nichols
Nov 7 2009 7:35AM
Follow google news

Network and server admins affected.

The discovery of a new flaw in the Secure Socket Layer (SSL) protocol is prompting networking and security vendors to issue warnings.

Mobile security vendor PhoneFactor said that the vulnerability was discovered in the transmission of data through SSL connections.

The flaw could allow an attacker to execute a 'man in the middle' attack in which information is altered and then sent without user knowledge.

According to PhoneFactor, the flaw is present in the SSL standard itself, meaning that all systems using the protocol could be vulnerable to attack.

"Because this is a protocol vulnerability, and not merely an implementation flaw, the impacts are far-reaching," said PhoneFactor chief technology officer Steve Dispensa.

"All SSL libraries will need to be patched, and most client and server applications will, at a minimum, need to include new copies of SSL libraries in their products."

No attacks in the wild have yet been reported, and PhoneFactor said that major hardware, networking and server software vendors were notified and advised more than one month prior to disclosing the flaw.

Tim Callan, vice president of marketing at VeriSign, told V3.co.uk that his company's researchers do not believe that the flaw poses a major risk to end users.

Callan explained that, although the vulnerability allows an attacker to add malicious code to outgoing SSL traffic, it does not allow an attacker to decrypt the information and spy on the data being sent.

Instead, the flaw functions in a similar way to a hole in the firewall, allowing attack code to slip through server security protections as trusted SSL data.

"There is no opportunity to spy on your bank account or anything like that," said Callan. "Essentially this is a network vulnerability. Once the malicious code is inside, you have a whole world of exploits that can be performed."

Callan said that the vulnerability is far-reaching, but is not on the level of previous widespread flaws, such as the 2008 DNS vulnerability.

"It is clever but, in terms of the real world, it will not have a large impact," he said. "At this point we are in the normal realm of security vulnerability patching."

Network and server administrators will need to download and install a patch from operating system vendors, but end users will not need to install any urgent updates.

SSL flaw prompts security scramble

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:
flawhardwarenetworkingsecurityserversslvulnerability

Related Articles

  • Marathon OAIC investigation finds Optus breached 51,000 customers' privacy Marathon OAIC investigation finds Optus breached 51,000 customers' privacy
  • US gov shortens cyber fix window to three days US gov shortens cyber fix window to three days
  • Kmart Group to expand RFID tagging to more products and to Target Kmart Group to expand RFID tagging to more products and to Target
  • Anthropic releases Mythos-class model for public use Anthropic releases Mythos-class model for public use
Join our WhatsApp Channel

Partner Content

CommBank creates opportunities for technologists to upskill  with frontier AI companies
Partner Content CommBank creates opportunities for technologists to upskill with frontier AI companies
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
AI is delivering business value today
Partner Content AI is delivering business value today
From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Promoted Content From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale

Sponsored Whitepapers

When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.