Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • E-Books
  • Lounge
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>In the Wild>SSL authentication flaw puts browsers at risk

SSL authentication flaw puts browsers at risk

Tweet

Robert vamosi By Robert Vamosi

A hole discovered recently in Secure Sockets Layer (SSL) HTTP sessions is difficult to exploit but may necessitate a revision of the SSL protocol itself.

The big-name browser vendors are quietly working to patch the vulnerability before the bad guys figure out how to use it to crack secure Web connections.


Transport Layer Security protocol exploitable

Last August, while researching various applications used by two-factor authentication vendor PhoneFactor, researcher Marsh Ray discovered something odd in the way the SSL Transport Layer Security (TLS) protocol handled authentication renegotiation. Ray was able to write an exploit that would, under certain circumstances, allow a man-in-the-middle attack to eavesdrop on SSL sessions used for e-commerce and online banking.

The flaw allows the attacker to join an authenticated SSL session and execute commands. After Ray proved the exploit to his bosses, he chose not to go public and instead followed Dan Kaminsky’s example after he discovered a major DNS flaw in 2008. (WS contributing editor Ryan Russell described the DNS vulnerability in his July 17, 2008, Perimeter Scan column.)

Just as Kaminsky did last year, Ray quietly contacted the vendors most affected by the SSL/TLS flaw and worked in the background to implement a fix before the malware writers got word of it. In September, Google even hosted a meeting at its Mountain View, CA, campus that produced a tentative draft proposal for the Internet Engineering Task Force (IETF). Microsoft had hosted a similar meeting on the DNS flaw for Kaminsky last year.

On Nov. 4 — quite independently — another researcher, Martin Rex of SAP, went public on the IETF TLS mailing list with his discovery of flaws within channel bindings that also affect TLS. A lively and extended discussion ensued.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.

Related posts:

  1. Cloud computing puts your health data at risk
  2. NNTP flaw could allow remote code execution
  3. Flaw in RealPlayer ready to be exploited
  4. Another unpatched IE flaw?
  5. Zipped folders flaw could allow remote code execution
= Paid content

All Windows Secrets articles posted on 2009-11-12:

  • Bonus How to get the most from Windows 7
  • Top Story Clean-install Windows 7 from the upgrade disc
  • Known Issues Readers offer more ways to enhance Windows 7
  • Wacky Web Week Invisible rope trips up unsuspecting passers-by
  • LangaList Plus Wanted: a free, novice-proof disk wiper
  • In the Wild SSL authentication flaw puts browsers at risk
  • Patch Watch XP patch removes threat of malicious Web fonts
  •  Show all articles on a single page
Robert Vamosi

About Robert Vamosi

WS contributing editor Robert Vamosi CISSP, was senior editor of CNET.com from 1999 to 2008 and winner of the 2005 MAGGIE Award for best regularly featured Web column for consumers. He is the author of When Gadgets Betray Us (Basic Books 2011)
View all posts by Robert Vamosi →
E-books

We’ve pored through years of back issues, picking the best tips, to create these ebooks:

E-book series
  • PC Maintenance Guide
  • PC Security Guide
  • Windows 7 Guide Vol 1
  • Windows 7 Guide Vol 2
  • Win XP Survival Guide
See the e-book series
Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.53
  • The sorry tale of the (un)Secure Sockets Layer 4.42
  • RPV: Win7′s least-known data-protection system 4.33
  • Recovery: the last step in total data security 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Pros and cons of a ‘keyfile’ password 4.21
  • Beating back Duku and a plethora of other threats 4.21
  • Office 2007 gets its final service pack 4.19
  • Putting Registry-/system-cleanup apps to the test 4.19
  • One year and 99 security bulletins later 4.18
  • 1.8TB external drive goes down hard 4.17
  • Don’t pay for software you don’t need — Part 3 4.16
  • Internet Explorer gets another round of patches 4.15
  • Is your free AV tool a ‘resource pig?’ 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Remote access leads to remote attacks 4.15
  • Keeping you up to date: say no to .NET — again 4.14
  • Take control of Google’s privacy policy settings 4.14
  • Office File Validation patch leads to problems 4.14
  • The advanced system-recover toolkit 4.13
  • New “419″ scam involves PayPal and Western Union 4.12
  • Readers’ best personal-privacy tips 4.11
  • Getting the most from Windows Search — Part 2 4.11
  • Re-examining Dropbox and its alternatives 4.10
  • Don’t pay for software you don’t need — Part 2 4.10
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb