Menu
Security experts warn of 'POODLE' attack against SSL 3.0

Security experts warn of 'POODLE' attack against SSL 3.0

Experts say that SSL 3.0 should be disabled even though some legacy products still use it

Google researchers have found a severe flaw in an obsolete but still used encryption software, which could be exploited to steal sensitive data.

The flaw in SSL 3.0 is more than 15 years old but is still used by modern web browsers and servers. SSL stands for "Secure Sockets Layer," which encrypts data between a client and server and secures most data sent over the Internet.

Bodo Möller, Thai Duong and Krzysztof Kotowicz of Google developed an attack called "POODLE," which stands for Padding Oracle On Downgraded Legacy Encryption, according to their research paper.

Web browsers are designed to use newer versions of SSL or TLS (Transport Layer Security), but most browsers will accommodate SSL 3.0 if that's all that a server can do on the other end.

The POODLE attack can force a connection to "fallback" to SSL 3.0, where it is then possible to steal cookies, which are small data files that enable persistent access to an online service. If stolen, a cookie could allow an attacker access to someone's Web-based email account, for example.

An attacker would have to control the network a victim is connected to in order to conduct this kind of man-in-the-middle attack. That might be possible in a public area, such as over a Wi-Fi network in an airport.

Security experts have long known SSL 3.0 was problematic. Matthew Green, a cryptographer and research professor at Johns Hopkins University, wrote on his blog that many servers still support SSL 3.0 since they didn't want to lockout users of Internet Explorer 6, a very dated but still used browser.

"The problem with the obvious solution is that our aging Internet infrastructure is still loaded with crappy browsers and servers that can't function without SSLv3 support," Green wrote.

"Browser vendors don't want their customers to hit a blank wall anytime they access a server or load balancer that only supports SSLv3, so they enable fallback," he wrote.

Google has already taken steps to stop encrypted connections from being made using less secure versions of SSL and TLS.

Adam Langley, who works on Google's Chrome browser, wrote on his blog that connections made using Chrome to Google's infrastructure are using a mechanism called "TLS_FALLBACK_SCSV", which prevents downgrading.

"We are urging server operators and other browsers to implement it too," Langley wrote. "It doesn't just protect against this specific attack, it solves the fallback problem in general."

Google is preparing a patch for Chrome that would forbid falling back to SSL 3.0 for all servers, but "this change will break things and so we don't feel that we can jump it straight to Chrome's stable channel. But we do hope to get it there within weeks and so buggy servers that currently function only because of SSL 3.0 fallback will need to be updated."

Major internet companies are already making adjustments to prevent a POODLE attack. CloudFlare, which has a widely used caching service, has disabled SSL 3.0 across its network by default for all of its customers, wrote CEO Matthew Prince.

"This will have an impact on some older browsers, resulting in an SSL connection error," Prince wrote. "The biggest impact is Internet Explorer 6 running on Windows XP or older."

Prince wrote that just 0.65 percent of the HTTPS encrypted traffic on CloudFlare's network uses SSL 3.0. "The good news is most of that traffic is actually attack traffic and some minor crawlers," he wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags GooglesecurityCloudFlareencryption

Featured

Slideshows

Educating from the epicentre - Why distributors are the pulse checkers of the channel

Educating from the epicentre - Why distributors are the pulse checkers of the channel

​As the channel changes and industry voices deepen, the need for clarity and insight heightens. Market misconceptions talk of an “under pressure” distribution space, with competitors in that fateful “race for relevance” across New Zealand. Amidst the cliched assumptions however, distribution is once again showing its strength, as a force to be listened to, rather than questioned. Traditionally, the role was born out of a need for vendors and resellers to find one another, acting as a bridge between the testing lab and the marketplace. Yet despite new technologies and business approaches shaking the channel to its very core, distributors remain tied to the epicentre - providing the voice of reason amidst a seismic industry shift. In looking across both sides of the vendor and partner fences, the middle concept of the three-tier chain remains centrally placed to understand the metrics of two differing worlds, as the continual pulse checkers of the local channel. This exclusive Reseller News Roundtable, in association with Dicker Data and rhipe, examined the pivotal role of distribution in understanding the health of the channel, educating from the epicentre as the market transforms at a rapid rate.

Educating from the epicentre - Why distributors are the pulse checkers of the channel
Kiwi channel reunites as After Hours kicks off 2017

Kiwi channel reunites as After Hours kicks off 2017

After Hours made a welcome return to the channel social calendar last night, with a bumper crowd of distributors, vendors and resellers descending on The Jefferson in Auckland to kickstart 2017. Photos by Maria Stefina.

Kiwi channel reunites as After Hours kicks off 2017
Arrow exclusively introduces Tenable Network Security to A/NZ channel

Arrow exclusively introduces Tenable Network Security to A/NZ channel

Arrow Electronics introduced Tenable Network Security to local resellers in Sydney last week, officially launching the distributor's latest security partnership across Australia and New Zealand. Representing the first direct distribution agreement locally for Tenable specifically, the deal sees Arrow deliver security solutions directly to mid-market and enterprise channel partners on both sides of the Tasman.

Arrow exclusively introduces Tenable Network Security to A/NZ channel
Show Comments