Subscribe free to our newsletters via your




CYBER WARS
Newly found online security flaw stems from 1990s
By Rob Lever
Washington (AFP) March 3, 2015


A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday.

The flaw dubbed "FREAK" could leave thousands of websites open to attacks if the problem is not patched, according to papers released by French and US researchers.

The flaw was discovered by a team led by Karthikeyan Bhargavan at INRIA in Paris -- the French Institute for Research in Computer Science and Automation -- and disclosure coordinated by Matthew Green, a cryptographer at Johns Hopkins University.

A research paper said the flaw comes from "a class of deliberately weak export cipher suites... introduced under the pressure of US government agencies to ensure that the NSA would be able to decrypt all foreign encrypted communication."

Green said in a blog post that even some sites maintained by the National Security Agency and FBI appeared to be vulnerable.

"Since the NSA was the organization that demanded export-grade crypto, it's only fitting that they should be the first site affected by this vulnerability," Green said.

Green and other researchers said the flaw stems from US government-imposed standards for encryption in software that was exported -- a short-lived effort to allow the United States to be able to access software exported to unfriendly regimes.

- Part of the software -

Even after it became legal to export strong encryption, the export mode feature was not removed from because some software still depended on it, according to Ed Felten, a Princeton University computer science professor.

"The flaw is significant in itself, but it is also a good example of what can go wrong when government asks to build weaknesses into security systems," said Felten in a blog post.

"Many web sites are vulnerable to this attack, allowing an adversary in the network to spoof or spy on traffic to vulnerable sites."

Felten said that the vulnerability on the NSA site is "not a big national security problem in itself because NSA doesn't distribute state secrets from its public site. But there is an important lesson here about the consequences of crypto policy decisions."

Green said Facebook's site which operates the "like" button was identified as vulnerable but later patched.

Green said the most of the flaws "will soon be patched" but that the flaw is important at a time when the NSA is seeking to maintain access to encrypted software and devices for national security reasons.

"The moral of this story is pretty simple: Encryption backdoors will always turn around and bite you in the ass," he wrote.


Thanks for being here;
We need your help. The SpaceDaily news network continues to grow but revenues have never been harder to maintain.

With the rise of Ad Blockers, and Facebook - our traditional revenue sources via quality network advertising continues to decline. And unlike so many other news sites, we don't have a paywall - with those annoying usernames and passwords.

Our news coverage takes time and effort to publish 365 days a year.

If you find our news sites informative and useful then please consider becoming a regular supporter or for now make a one off contribution.
SpaceDaily Contributor
$5 Billed Once


credit card or paypal
SpaceDaily Monthly Supporter
$5 Billed Monthly


paypal only


.


Related Links
Cyberwar - Internet Security News - Systems and Policy Issues






Comment on this article via your Facebook, Yahoo, AOL, Hotmail login.

Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle




Memory Foam Mattress Review
Newsletters :: SpaceDaily :: SpaceWar :: TerraDaily :: Energy Daily
XML Feeds :: Space News :: Earth News :: War News :: Solar Energy News





CYBER WARS
US spymaster warns over low-level cyber attacks
Washington (AFP) Feb 26, 2015
A steady stream of low-level cyber attacks poses the most likely danger to the United States rather than a potential digital "armageddon," US intelligence director James Clapper said on Thursday. US officials for years have warned of a possible "cyber Pearl Harbor" that could shut down financial networks, poison water supplies or switch off power grids. But Clapper told lawmakers that A ... read more


CYBER WARS
Afghan president pledges relief fund for avalanche victims

Death toll from Afghan avalanches tops 200: officials

US Nuclear Facility Miscalculated Workers' Radiation Exposure

Kazakhstan Evacuating Village Where People Fall Asleep At Random

CYBER WARS
Study of Atmospheric 'Froth' May Help GPS Communications

Indian company to produce Sagem navigational system

Tehran keeps tighter leash on strays with GPS collars

China, Russia strengthen satellite navigation cooperation

CYBER WARS
Mystery of the reverse-wired eyeball solved

How does the human brain tackle problems it did not evolve to solve?

Nanotech and genetic interference may tackle untreatable brain tumors

Brain makes decisions with same method used to break WW2 Enigma code

CYBER WARS
American birders anxious to explore, protect Cuban species

China ivory carving ban a 'symbolic' move: wildlife group

How mantis shrimp evolved many shapes with same powerful punch

Salish Sea seagull populations halved since 1980s

CYBER WARS
Zombie outbreak? Statistical mechanics reveal the ideal hideout

Cholera epidemic kills 41 in Mozambique

Parasitism runs deep in malaria's family tree

Quick test for Ebola

CYBER WARS
China official jailed for 17 years over jade bribes

Hong Kong police arrest 33 after anti-mainland march

New media, New China: Xinhua relaunch on barred networks

China's leaders meet with 'rule of law' on agenda

CYBER WARS
Sagem-led consortium intoduces anti-piracy system

China arrests Turks, Uighurs in human smuggling plot: report

Two police to hang for murder in Malaysian corruption scandal

Nobel protester sought to draw attention to 'murdered Mexican students'

CYBER WARS
China manufacturing improves in February: HSBC

China manufacturing shrinks again in February: govt

Protests blamed as Hong Kong misses growth targets

Britain's Standard Chartered bank says CEO to depart




The content herein, unless otherwise known to be public domain, are Copyright 1995-2014 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. Privacy Statement All images and articles appearing on Space Media Network have been edited or digitally altered in some way. Any requests to remove copyright material will be acted upon in a timely and appropriate manner. Any attempt to extort money from Space Media Network will be ignored and reported to Australian Law Enforcement Agencies as a potential case of financial fraud involving the use of a telephonic carriage device or postal service.