Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
SSL After The Heartbleed
Newest First  |  Oldest First  |  Threaded View
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
5/29/2014 | 10:27:14 PM
Re: SSL and the Fallacies
@theb0x - agreed.  Love: TCP MAC option.

http://tools.ietf.org/html/draft-bittau-tcp-crypt-04#page-39
theb0x
50%
50%
theb0x,
User Rank: Ninja
5/29/2014 | 8:51:59 PM
Re: SSL and the Fallacies
I would like to see more development in something like tcpcrypt.
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
5/28/2014 | 2:59:20 PM
Ugh
I kind of hate SSL. It's not exactly the technology that I hate. It's the faith people put in it. I think people think it's way better than it is, and I don't think we've done a very good job of telling the general public about what it really is and isn't. It's just "the browser bar is green, so you're perfectly safe, always, everywhere." I think most people give it too much credit.
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
5/28/2014 | 4:37:00 AM
SSL and the Fallacies
Those familiar with the Fallacies of Distributed Computing [http://en.wikipedia.org/wiki/Fallacies_of_Distributed_Computing] may give pause to the statement "'always-on' SSL, the notion of encrypting everything, is what we should strive for".

As with any technology, the more encryption you lay over it, the harder cyber-criminals will work to crack it, from tricking users to accept a bad certificate, obtaining valid certificates and using them maliciously, SSLStrip (stripping away the S in HTTPS and dropping the using into masked HTTP), cracking SSL keys, to side-channel attacks like Browser Reconnaissance and Exfiltration via Adaptive Compression of Hypertext [BREACH] which leverages compression and takes advantage of HTTP responses, which are compressed using mechanisms such as gzip; SSL will always be under attack.

Let's see some thoughtful and innovative approaches to the social side of the security and privacy problem first, before we simply throw more tech (or money) at it. 


AI Is Everywhere, but Don't Ignore the Basics
Howie Xu, Vice President of AI and Machine Learning at Zscaler,  9/10/2019
Fed Kaspersky Ban Made Permanent by New Rules
Dark Reading Staff 9/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-4147
PUBLISHED: 2019-09-16
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 158413.
CVE-2019-5481
PUBLISHED: 2019-09-16
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
CVE-2019-5482
PUBLISHED: 2019-09-16
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
CVE-2019-15741
PUBLISHED: 2019-09-16
An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation
CVE-2019-16370
PUBLISHED: 2019-09-16
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.