Website danger as hacker breaks SSL encryption
The Black Hat conference in the US shows that software can be used to steal information from sites you may think are secure.

Independent hacker Moxie Marlinspike has unveiled new techniques to defeat SSL encryption, which would leave common web applications such as online banking or secure website logins vulnerable to attack.
This would mean that the padlock icon in the corner of supposedly safe' websites and touted as optimal security by companies like Verisign may not be as safe as people generally believe.
Marlinspike revealed his findings at the Black Hat security conference in Washington DC, showing a number of ways where the "chain of trust" fell apart around SSL encryption.
He looked at the possibilities for new vectors of attack against HTTPS, the combination of HTTP and a network security protocol, which are often used for payment and sensitive corporate transactions.
Marlinspike also revealed a free software tool called "SSL Strip", which could be deployed on a network and used for a man in the middle attack on all potential SSL connections.
It stripped away the SSL encryption, substituting a look-alike HTTPS site, while still convincing the user and website the security was in place.
He claimed that by using a real world attack on several secure websites such as PayPal, Gmail, Ticketmaster and Facebook, he garnered 117 email accounts, 16 credit card numbers, seven PayPal logins and 300 other miscellaneous secure logins.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Click here for a video interview with Marlinspike.
The SSL encryption hack wasn't the only threat highlighted at Black Hat. Zscaler security researcher Michael Sutton sounded a warning against features that allowed offline access to websites.
He stressed that offline web applications such Gmail and Gears were secure, but warned that other sites with poor security risked visitors losing their data.
As well, Vietnamese researcher Duc Nguyen also demonstrated how he and his partners cracked the facial recognition technology used by Lenovo, Asus and Toshiba on their laptops.
They cracked the tech simply by using a picture of a person instead of their real face, as well as by presenting multiple phony facial images.
The researchers concluded that it was sufficient evidence that the biometric authentication used by the manufacturers was not secure enough.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
Hacked PayPal accounts tripled in value during pandemic
News But value of hacked credit cards decline, according to survey
By Rene Millman
-
PayPal to put hate group funding under the microscope
News It will research how extremists are using payment platforms for funding
By Mike Brassfield
-
PayPal's authentication is no challenge for one hacker
News The white hat hacker said he could bypass the two-step security measures used to protect customer accounts
By Clare Hopping
-
Pressure mounts on US justice department to drop Wikileaks investigation
News Human rights organisations claim investigation could put all journalists at risk of prosecution
By Caroline Donnelly
-
Anonymous hackers admit involvement in 2010 PayPal cyber attack
News Anonymous group members plead guilty to taking part in DDoS attack against PayPal.
By Rene Millman
-
Anonymous DDoS attacks cost PayPal £3.5m, court hears
News Northampton student pleads not guilty to charges relating to attacks on online payment portal.
By Caroline Donnelly
-
Anonymous, LulzSec go legal in PayPal war?
News Anonymous and LulzSec claim success already in attempts to get people to ditch their PayPal accounts.
By Tom Brewster
-
UK teen detained as FBI makes PayPal attack arrests
News Anonymous is being hunted by police across the world, with 20 arrests made in relation to high profile cyber attacks.
By Tom Brewster