| Home : June 16 2014 Computer News : Popular websites still vulnerable to OpenSSL hijacking attack |
|
Popular websites still vulnerable to OpenSSL hijacking attack |
June 16, 2014
Some of the Internet’s most visited websites that encrypt data with the SSL protocol are still susceptible to a recently announced vulnerability that could allow attackers to intercept and decrypt connections.On June 5, developers of the widely used OpenSSL crypto library released emergency security patches to address several vulnerabilities, including one tracked as CVE-2014-0224 that could allow attackers to spy on encrypted connections if certain conditions are met.Until a few years ago, full-session encryption via HTTPS (HTTP with SSL) was mainly used by financial, e-commerce, and other sites dealing with sensitive information. However, the increasing use of mobile devices that often connect over insecure wireless networks, coupled with the past year’s revelations of upstream bulk data collection by spy agencies, led to a large number of sites adding support for it.To read this article in full or to leave a comment, please click here
Link: http://www.pcworld.com/article/2364080/popular-https-sites-still-vulnerable-to-openssl-connection-hijacking-attack.html#tk.rss_all
|
|
|
|
|