Breaking News

G.SKILL Showcases DDR5-9200 1.1V 16GBx2 High-Speed CU-DIMM Memory Kit Sony Introduces BRAVIA 9 II and BRAVIA 7 II RGB TVs and the BRAVIA Theatre Trio Creative Announces Sound Blaster AE-X Acer Expands Gaming Portfolio With Predator Atlas 8 Handheld Powered by Intel COLORFUL Presents Limited Edition iGame GeForce RTX 5070 Ultra OC 12GB x 007 First Light Edition

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Google Reveals Flaw in SSL Protocol

Google Reveals Flaw in SSL Protocol

Enterprise & IT Oct 15,2014 0

Google has disclosed details of a vulnerability in the design of SSL version 3.0, which is is nearly 15 years old but remains widespread. According to the team's Bodo Möller: "This vulnerability allows the plaintext of secure connections to be calculated by a network attacker."

While SSL 3.0 has been succeeded by Transport Layer Security (TLS) 1.0, TLS 1.1, and TLS 1.2, many TLS implementations have continued to be backwards compatible with SSL 3.0 to work with legacy systems for a smoother user experience.

Nearly all browsers support SSL 3.0 and, in order to work around bugs in HTTPS servers, browsers will retry failed connections with older protocol versions, including SSL 3.0. Because a network attacker can cause connection failures, they can trigger the use of SSL 3.0 and then exploit this issue.

Disabling SSL 3.0 support, or CBC-mode ciphers with SSL 3.0, is sufficient to mitigate this issue, but presents significant compatibility problems, even today. Therefore Google's recommended response is to support TLS_FALLBACK_SCSV. This is a mechanism that solves the problems caused by retrying failed connections and thus prevents attackers from inducing browsers to use SSL 3.0. It also prevents downgrades from TLS 1.2 to 1.1 or 1.0 and so may help prevent future attacks.

Google Chrome and Google's servers have supported TLS_FALLBACK_SCSV since February. Additionally, Google Chrome will begin testing changes today that disable the fallback to SSL 3.0.

Google hopes to eventually remove support for SSL 3.0 completely from its client products.

To prevent attacks on Firefox, open about.config, search for "security.enable," and set "security.enable_ssl3" to false.

To stop them on IE, go to the tools menu, click Internet Options and head to the Advanced tab. Under that look for the Security heading, and make sure that the SSL 3.0 check box is unchecked.

Tags: Google
Previous Post
Samsung Claims 5G Speed Record
Next Post
Samsung's 840 EVO Firmware Update Fixes Read Issues

Related Posts

  • Google announces Pixel 10, Pixel 10 Pro Fold and Pixel Buds 2a

  • Elevate your gameplay across mobile and PC

  • What’s new in Android 15, plus more updates

  • NVIDIA Teams Up With Google DeepMind to Drive Large Language Model Innovation

  • Google at CES 2024

  • Google introduces Gemini AI model

  • Google Cloud Launches AI-Powered Anti Money Laundering Product for Financial Institutions

  • Connecting all things Android at MWC Barcelona

Latest News

G.SKILL Showcases DDR5-9200 1.1V 16GBx2 High-Speed CU-DIMM Memory Kit
PC components

G.SKILL Showcases DDR5-9200 1.1V 16GBx2 High-Speed CU-DIMM Memory Kit

Sony Introduces BRAVIA 9 II and BRAVIA 7 II RGB TVs and the BRAVIA Theatre Trio
Consumer Electronics

Sony Introduces BRAVIA 9 II and BRAVIA 7 II RGB TVs and the BRAVIA Theatre Trio

Creative Announces Sound Blaster AE-X
PC components

Creative Announces Sound Blaster AE-X

Acer Expands Gaming Portfolio With Predator Atlas 8 Handheld Powered by Intel
Gaming

Acer Expands Gaming Portfolio With Predator Atlas 8 Handheld Powered by Intel

COLORFUL Presents Limited Edition iGame GeForce RTX 5070 Ultra OC 12GB x 007 First Light Edition
GPUs

COLORFUL Presents Limited Edition iGame GeForce RTX 5070 Ultra OC 12GB x 007 First Light Edition

Popular Reviews

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Endorfy Thock V2 Wireless Keyboard

Endorfy Thock V2 Wireless Keyboard

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Crucial T710 2TB NVME SSD

Crucial T710 2TB NVME SSD

JSAUX 65Wh Rog Ally Battery

JSAUX 65Wh Rog Ally Battery

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed