<br />
<b>Deprecated</b>:  Function create_function() is deprecated in <b>/home/hidefide/public_html/blog/wp-content/plugins/wr-pagebuilder/core/core.php</b> on line <b>127</b><br />
{"id":217,"date":"2016-09-25T13:04:35","date_gmt":"2016-09-25T13:04:35","guid":{"rendered":"https:\/\/icaruspressblog.wordpress.com\/?p=217"},"modified":"2019-04-17T12:14:47","modified_gmt":"2019-04-17T12:14:47","slug":"holy-insert-expletive-here-et-tu-ssl","status":"publish","type":"post","link":"https:\/\/hidefideas.com\/blog\/2016\/09\/25\/holy-insert-expletive-here-et-tu-ssl\/","title":{"rendered":"\u201cHoly [Insert Expletive Here]! Et Tu, SSL?\u201d"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\" size-full wp-image-219 alignright\" src=\"http:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/dangerwillrobinson.jpg\" alt=\"DangerWillRobinson\" width=\"286\" height=\"362\" srcset=\"https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/dangerwillrobinson.jpg 286w, https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/dangerwillrobinson-237x300.jpg 237w, https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/dangerwillrobinson-119x150.jpg 119w\" sizes=\"auto, (max-width: 286px) 100vw, 286px\" \/>In a world where the only thing standing between us and the spammers, phishers and hackers is a little piece of tunneling security that keeps IT admins dreaming about warm and snuggly things, the idea of that security being breached is a beastly demon no one could have envisioned. Unfortunately, the pleasant dreams are over and the BEAST is a nightmare that will rock the Internet world, and warm milk ain\u2019t gonna fix this one, folks.<!--more--><\/p>\n<p>When I go to sleep at night, I do it with the comforting belief that when I awake in the morning and put my feet on the floor, there will be a floor underneath me. In much the same way, I traverse the web knowing full-well that my surfing habits, private information and transactions are snugly tucked away inside a warm blanket of encryption known as SSL\/TLS. So when the floor gets yanked out from underneath my feet, you can understand how I might get a little pissed off. And that\u2019s exactly how I felt this morning when I discovered that the floor that protected me from the creeps has begun to sway, as if I had just spent Saturday night at the pub and the floor wasn\u2019t particularly happy about it.<\/p>\n<p>If you want to share the experience, look no further than <em>The Register<\/em>, which is <a href=\"http:\/\/www.theregister.co.uk\/2011\/09\/19\/beast_exploits_paypal_ssl\/\">reporting<\/a> that at the <a href=\"Ekoparty%20security%20conference\">Ekoparty security conference<\/a> in Buenos Aires last week, researchers Thai Duong and Juliano Rizzo unveiled their work \u2013 BEAST, short for Browser Exploit Against SSL\/TLS \u2013 which attacks TLS and SSL, the protocols that heretofore kept us warm at night. BEAST is a nifty piece of JavaScript that works alongside a network sniffer to decrypt user account cookies and gain access to restricted user accounts. Yes, you heard it right.<\/p>\n<h2><strong>Sing Along: It\u2019s the End of the World as We Know it<br \/>\n\u2026Or is it?<\/strong><\/h2>\n<p>Duong and Rizzo made news last year when they unveiled a <a href=\"http:\/\/www.theregister.co.uk\/2010\/06\/08\/padding_oracle_attack_tool\/\">point-and-click tool<\/a> that exposes private information and executes arbitrary code. According to Duong, the demo decrypted an authentication cookie used to access a PayPal account. The exploit of SSL and TLS is not a new idea, actually, since the idea was <a href=\"http:\/\/www.mail-archive.com\/openssl-dev@openssl.org\/msg10664.html\">conceived back in 2002<\/a>; but for years it\u2019s been considered theoretical at best \u2013 until now, that is. Duong noted in an email published by <em>The Register<\/em> that \u201cBEAST is different than most published attacks against HTTPS. While other attacks focus on the authenticity property of SSL, BEAST attacks the confidentiality of the protocol. As far as we know, BEAST implements the first attack that actually decrypts HTTPS requests.\u201d<\/p>\n<p>In case you\u2019re wondering how many canned goods you have in the pantry, worry not: it\u2019s not yet time to strip naked and run through the streets proclaiming the end of the world. \u201cThe vulnerability resides in versions 1.0 and earlier of TLS, or transport layer security, the successor to the&nbsp;secure sockets layer technology&nbsp;that serves as the internet&#8217;s foundation of trust,\u201d <em>The Register<\/em> reports.<\/p>\n<p>It\u2019s not all good news, though. \u201cAlthough versions 1.1 and 1.2 of TLS aren&#8217;t susceptible, they remain almost entirely unsupported in browsers and websites alike, making encrypted transactions on PayPal, GMail, and just about every other website vulnerable to eavesdropping by hackers who are able to control the connection between the end user and the website he&#8217;s visiting.\u201d<\/p>\n<p>Furthermore, independent security analyst Trevor Perrin writes, \u201cBEAST is like a cryptographic Trojan horse \u2013 an attacker slips a bit of JavaScript into your browser, and the JavaScript collaborates with a network sniffer to undermine your HTTPS connection. If the attack works as quickly and widely as [Duong and Rizzo] claim, it&#8217;s a legitimate threat.\u201d<\/p>\n<p><strong>Note: <\/strong>Those who run a web server and who may be concerned about security should modify the servers to favor the rc4-sha cipher, which is widely supported and not vulnerable to the attack unveiled by Duong and Rizzo.<\/p>\n<h2><strong>Time to Call Some People Out<\/strong><\/h2>\n<p>It\u2019s being <a href=\"http:\/\/nakedsecurity.sophos.com\/2011\/09\/24\/secure-web-browsing-cracked-by-beast\/\">reported<\/a> that, \u201cDuong and Rizzo tipped off the major browser vendors about their findings months ago but so far the only response appears to have come from the folks at Chrome. A fix for the attack is currently under test in the development version of their browser.\u201d<\/p>\n<p>REALLY? Shame on you, browser makers. Not surprisingly, two days after The Register first published their article, Google released a developer version of its Chrome browser designed to thwart the attack.<\/p>\n<p>Time to go and huddle in a corner. Now, where did I put that tin foil hat?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In a world where the only thing standing between us and the spammers, phishers and hackers is a little piece of tunneling security that keeps&hellip; <\/p>\n","protected":false},"author":3,"featured_media":219,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20,13,14],"tags":[11,9,10,8,7],"class_list":["post-217","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-humor","category-security","category-spam","tag-allspammedup","tag-bot","tag-botnet","tag-malware","tag-spam","jsn-master"],"_links":{"self":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/217","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/comments?post=217"}],"version-history":[{"count":3,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/217\/revisions"}],"predecessor-version":[{"id":1838,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/217\/revisions\/1838"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/media\/219"}],"wp:attachment":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/media?parent=217"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/categories?post=217"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/tags?post=217"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}