Major SSL encryption flaw hits the web
Tech companies using SSL have some serious work to do to fix a big hole that could leave internet users at risk.

A major' vulnerability in SSL (Secure Sockets Layer) authentication has been discovered, potentially leaving web surfers under serious threat.
The authentication gap allows an attacker to perform a man-in-the-middle' attack, according to security researchers at PhoneFactor.
PhoneFactor claimed that most websites using SSL encryption were affected, including online banking and retail sites. Some mail and database servers were also vulnerable.
It also invalidated the SSL lock, which is used to verify whether website communications are secure.
Researchers Marsh Ray and Steve Dispensa are believed to have shown the flaw to a working group of affected vendors, which included Microsoft, Intel, Nokia, IBM, Cisco and Juniper.
In a statement, PhoneFactor said: "[We] volunteered to delay disclosure on the vulnerability until early 2010 to allow time for vendors to make the necessary patches available."
"However, an independent researcher discovered the vulnerability and posted it to Internet Engineering Task Force (IETF) mailing list on November 4th... News of the vulnerability quickly spread through the IT security community," it added.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
PhoneFactor added that this was a protocol vulnerability rather than an implementation flaw, so the impact was far reaching.
"All SSL libraries will need to be patched, and most client and server applications will, at a minimum, need to include new copies of SSL libraries in their products," the firm said.
"Most users will eventually need to update any software that uses SSL."
Andrew Clarke, senior vice president for Lumension, said in a statement that the SSL flaw was likely to bring a large number of patches in the near term from vulnerable vendors.
-
Leaked Nvidia certificates used to sign malware bypassing Windows detection
News Windows admins are advised to implement custom policies to avoid seemingly legitimate malware making its way into corporate environments
By Connor Jones
-
GoDaddy data breach exposes over 1.2 million customer details
News Attacker had access to admin passwords for over two months
By Danny Bradbury
-
Why is SSL under attack?
In-depth Don't get sidetracked by a storm in the SSL teacup, warns Davey Winder...
By Davey Winder
-
Facebook warns of new Superfish threat
News The fake security certificate used by the Lenovo-installed adware can be re-used by hackers, says social network
By Joe Curtis
-
OS X Mavericks update to fix major security flaw in Macs
News Apple follows iOS 7 update with Mac OS X Mavericks patch to address encryption issues.
By Caroline Donnelly
-
Who to trust after the VeriSign hack?
In-depth Davey Winder questions what data was stolen from VeriSign and wonders why the company hasn't been more forthcoming.
By Davey Winder
-
SSL under threat as flaw exploited
News Fears over the security credentials of SSL rise after researchers claim to have found a way to exploit a long-known vulnerability.
By Tom Brewster
-
MI6 targeted in DigiNotar hack
News MI6, the CIA and Facebook were all targeted following a hack on certificate authority DigiNotar.
By Tom Brewster