Breaking News

ASUS Announces T1 GeForce RTX 5070 and RTX 5060 Ti Graphics Cards COLORFUL Launches iGame B850M ULTRA Series Micro-ATX Motherboards Sony Unveils 1000X THE COLLEXION Samsung Launches Next-Gen Odyssey, ViewFinity and The Movingstyle Essential Monitors LG Electronics Introduces World’s First Native 1000Hz Full HD Gaming Monitor

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Google Reveals Flaw in SSL Protocol

Google Reveals Flaw in SSL Protocol

Enterprise & IT Oct 15,2014 0

Google has disclosed details of a vulnerability in the design of SSL version 3.0, which is is nearly 15 years old but remains widespread. According to the team's Bodo Möller: "This vulnerability allows the plaintext of secure connections to be calculated by a network attacker."

While SSL 3.0 has been succeeded by Transport Layer Security (TLS) 1.0, TLS 1.1, and TLS 1.2, many TLS implementations have continued to be backwards compatible with SSL 3.0 to work with legacy systems for a smoother user experience.

Nearly all browsers support SSL 3.0 and, in order to work around bugs in HTTPS servers, browsers will retry failed connections with older protocol versions, including SSL 3.0. Because a network attacker can cause connection failures, they can trigger the use of SSL 3.0 and then exploit this issue.

Disabling SSL 3.0 support, or CBC-mode ciphers with SSL 3.0, is sufficient to mitigate this issue, but presents significant compatibility problems, even today. Therefore Google's recommended response is to support TLS_FALLBACK_SCSV. This is a mechanism that solves the problems caused by retrying failed connections and thus prevents attackers from inducing browsers to use SSL 3.0. It also prevents downgrades from TLS 1.2 to 1.1 or 1.0 and so may help prevent future attacks.

Google Chrome and Google's servers have supported TLS_FALLBACK_SCSV since February. Additionally, Google Chrome will begin testing changes today that disable the fallback to SSL 3.0.

Google hopes to eventually remove support for SSL 3.0 completely from its client products.

To prevent attacks on Firefox, open about.config, search for "security.enable," and set "security.enable_ssl3" to false.

To stop them on IE, go to the tools menu, click Internet Options and head to the Advanced tab. Under that look for the Security heading, and make sure that the SSL 3.0 check box is unchecked.

Tags: Google
Previous Post
Samsung Claims 5G Speed Record
Next Post
Samsung's 840 EVO Firmware Update Fixes Read Issues

Related Posts

  • Google announces Pixel 10, Pixel 10 Pro Fold and Pixel Buds 2a

  • Elevate your gameplay across mobile and PC

  • What’s new in Android 15, plus more updates

  • NVIDIA Teams Up With Google DeepMind to Drive Large Language Model Innovation

  • Google at CES 2024

  • Google introduces Gemini AI model

  • Google Cloud Launches AI-Powered Anti Money Laundering Product for Financial Institutions

  • Connecting all things Android at MWC Barcelona

Latest News

ASUS Announces T1 GeForce RTX 5070 and RTX 5060 Ti Graphics Cards
GPUs

ASUS Announces T1 GeForce RTX 5070 and RTX 5060 Ti Graphics Cards

COLORFUL Launches iGame B850M ULTRA Series Micro-ATX Motherboards
PC components

COLORFUL Launches iGame B850M ULTRA Series Micro-ATX Motherboards

Sony Unveils 1000X THE COLLEXION
Consumer Electronics

Sony Unveils 1000X THE COLLEXION

Samsung Launches Next-Gen Odyssey, ViewFinity and The Movingstyle Essential Monitors
Enterprise & IT

Samsung Launches Next-Gen Odyssey, ViewFinity and The Movingstyle Essential Monitors

LG Electronics Introduces World’s First Native 1000Hz Full HD Gaming Monitor
Consumer Electronics

LG Electronics Introduces World’s First Native 1000Hz Full HD Gaming Monitor

Popular Reviews

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Endorfy Thock V2 Wireless Keyboard

Endorfy Thock V2 Wireless Keyboard

Crucial T710 2TB NVME SSD

Crucial T710 2TB NVME SSD

JSAUX 65Wh Rog Ally Battery

JSAUX 65Wh Rog Ally Battery

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed