Menu
Security experts warn of 'POODLE' attack against SSL 3.0

Security experts warn of 'POODLE' attack against SSL 3.0

Experts say that SSL 3.0 should be disabled even though some legacy products still use it

Google researchers have found a severe flaw in an obsolete but still used encryption software, which could be exploited to steal sensitive data.

The flaw in SSL 3.0 is more than 15 years old but is still used by modern web browsers and servers. SSL stands for "Secure Sockets Layer," which encrypts data between a client and server and secures most data sent over the Internet.

Bodo Möller, Thai Duong and Krzysztof Kotowicz of Google developed an attack called "POODLE," which stands for Padding Oracle On Downgraded Legacy Encryption, according to their research paper.

Web browsers are designed to use newer versions of SSL or TLS (Transport Layer Security), but most browsers will accommodate SSL 3.0 if that's all that a server can do on the other end.

The POODLE attack can force a connection to "fallback" to SSL 3.0, where it is then possible to steal cookies, which are small data files that enable persistent access to an online service. If stolen, a cookie could allow an attacker access to someone's Web-based email account, for example.

An attacker would have to control the network a victim is connected to in order to conduct this kind of man-in-the-middle attack. That might be possible in a public area, such as over a Wi-Fi network in an airport.

Security experts have long known SSL 3.0 was problematic. Matthew Green, a cryptographer and research professor at Johns Hopkins University, wrote on his blog that many servers still support SSL 3.0 since they didn't want to lockout users of Internet Explorer 6, a very dated but still used browser.

"The problem with the obvious solution is that our aging Internet infrastructure is still loaded with crappy browsers and servers that can't function without SSLv3 support," Green wrote.

"Browser vendors don't want their customers to hit a blank wall anytime they access a server or load balancer that only supports SSLv3, so they enable fallback," he wrote.

Google has already taken steps to stop encrypted connections from being made using less secure versions of SSL and TLS.

Adam Langley, who works on Google's Chrome browser, wrote on his blog that connections made using Chrome to Google's infrastructure are using a mechanism called "TLS_FALLBACK_SCSV", which prevents downgrading.

"We are urging server operators and other browsers to implement it too," Langley wrote. "It doesn't just protect against this specific attack, it solves the fallback problem in general."

Google is preparing a patch for Chrome that would forbid falling back to SSL 3.0 for all servers, but "this change will break things and so we don't feel that we can jump it straight to Chrome's stable channel. But we do hope to get it there within weeks and so buggy servers that currently function only because of SSL 3.0 fallback will need to be updated."

Major internet companies are already making adjustments to prevent a POODLE attack. CloudFlare, which has a widely used caching service, has disabled SSL 3.0 across its network by default for all of its customers, wrote CEO Matthew Prince.

"This will have an impact on some older browsers, resulting in an SSL connection error," Prince wrote. "The biggest impact is Internet Explorer 6 running on Windows XP or older."

Prince wrote that just 0.65 percent of the HTTPS encrypted traffic on CloudFlare's network uses SSL 3.0. "The good news is most of that traffic is actually attack traffic and some minor crawlers," he wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags GooglesecurityCloudFlareencryption

Featured

Slideshows

Sizing up the NZ security spectrum - Where's the channel sweet spot?

Sizing up the NZ security spectrum - Where's the channel sweet spot?

From new extortion schemes, outside threats and rising cyber attacks, the art of securing the enterprise has seldom been so complex or challenging. With distance no longer a viable defence, Kiwi businesses are fighting to stay ahead of the security curve. In total, 28 per cent of local businesses faced a cyber attack last year, with the number in New Zealand set to rise in 2017. Yet amidst the sensationalism, media headlines and ongoing high profile breaches, confusion floods the channel, as partners seek strategic methods to combat rising sophistication from attackers. In sizing up the security spectrum, this Reseller News roundtable - in association with F5 Networks, Kaspersky Lab, Tech Data, Sophos and SonicWall - assessed where the channel sweet spot is within the New Zealand channel. Photos by Maria Stefina.

Sizing up the NZ security spectrum - Where's the channel sweet spot?
Kiwi channel comes together for another round of After Hours

Kiwi channel comes together for another round of After Hours

The channel came together for another round of After Hours, with a bumper crowd of distributors, vendors and partners descending on The Jefferson in Auckland. Photos by Maria Stefina.​

Kiwi channel comes together for another round of After Hours
Consegna comes to town with AWS cloud offerings launch in Auckland

Consegna comes to town with AWS cloud offerings launch in Auckland

Emerging start-up Consegna has officially launched its cloud offerings in the New Zealand market, through a kick-off event held at Seafarers Building in Auckland.​ Founded in June 2016, the Auckland-based business is backed by AWS and supported by a global team of cloud specialists, leveraging global managed services partnerships with Rackspace locally.

Consegna comes to town with AWS cloud offerings launch in Auckland
Show Comments