Subscribe free to our newsletters via your
. 24/7 Space News .




CYBER WARS
Newly found online security flaw stems from 1990s
By Rob Lever
Washington (AFP) March 3, 2015


A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday.

The flaw dubbed "FREAK" could leave thousands of websites open to attacks if the problem is not patched, according to papers released by French and US researchers.

The flaw was discovered by a team led by Karthikeyan Bhargavan at INRIA in Paris -- the French Institute for Research in Computer Science and Automation -- and disclosure coordinated by Matthew Green, a cryptographer at Johns Hopkins University.

A research paper said the flaw comes from "a class of deliberately weak export cipher suites... introduced under the pressure of US government agencies to ensure that the NSA would be able to decrypt all foreign encrypted communication."

Green said in a blog post that even some sites maintained by the National Security Agency and FBI appeared to be vulnerable.

"Since the NSA was the organization that demanded export-grade crypto, it's only fitting that they should be the first site affected by this vulnerability," Green said.

Green and other researchers said the flaw stems from US government-imposed standards for encryption in software that was exported -- a short-lived effort to allow the United States to be able to access software exported to unfriendly regimes.

- Part of the software -

Even after it became legal to export strong encryption, the export mode feature was not removed from because some software still depended on it, according to Ed Felten, a Princeton University computer science professor.

"The flaw is significant in itself, but it is also a good example of what can go wrong when government asks to build weaknesses into security systems," said Felten in a blog post.

"Many web sites are vulnerable to this attack, allowing an adversary in the network to spoof or spy on traffic to vulnerable sites."

Felten said that the vulnerability on the NSA site is "not a big national security problem in itself because NSA doesn't distribute state secrets from its public site. But there is an important lesson here about the consequences of crypto policy decisions."

Green said Facebook's site which operates the "like" button was identified as vulnerable but later patched.

Green said the most of the flaws "will soon be patched" but that the flaw is important at a time when the NSA is seeking to maintain access to encrypted software and devices for national security reasons.

"The moral of this story is pretty simple: Encryption backdoors will always turn around and bite you in the ass," he wrote.


Thanks for being here;
We need your help. The SpaceDaily news network continues to grow but revenues have never been harder to maintain.

With the rise of Ad Blockers, and Facebook - our traditional revenue sources via quality network advertising continues to decline. And unlike so many other news sites, we don't have a paywall - with those annoying usernames and passwords.

Our news coverage takes time and effort to publish 365 days a year.

If you find our news sites informative and useful then please consider becoming a regular supporter or for now make a one off contribution.
SpaceDaily Contributor
$5 Billed Once


credit card or paypal
SpaceDaily Monthly Supporter
$5 Billed Monthly


paypal only


.


Related Links
Cyberwar - Internet Security News - Systems and Policy Issues






Comment on this article via your Facebook, Yahoo, AOL, Hotmail login.

Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle




Memory Foam Mattress Review
Newsletters :: SpaceDaily :: SpaceWar :: TerraDaily :: Energy Daily
XML Feeds :: Space News :: Earth News :: War News :: Solar Energy News





CYBER WARS
US spymaster warns over low-level cyber attacks
Washington (AFP) Feb 26, 2015
A steady stream of low-level cyber attacks poses the most likely danger to the United States rather than a potential digital "armageddon," US intelligence director James Clapper said on Thursday. US officials for years have warned of a possible "cyber Pearl Harbor" that could shut down financial networks, poison water supplies or switch off power grids. But Clapper told lawmakers that A ... read more


CYBER WARS
Application of laser microprobe technology to Apollo samples refines lunar impact history

NASA releases video of the far side of the Moon

US Issuing Licenses for Mineral Mining on Moon

LRO finds lunar hydrogen more abundant on Moon's pole-facing slopes

CYBER WARS
NASA's Curiosity Mars Rover Drills at 'Telegraph Peak'

How Can We Protect Mars From Earth, While Searching For Life

The Search For Volcanic Eruptions On Mars Reaches The Next Level

Using Curiosity to Search for Life

CYBER WARS
Old-economy sectors are now tech, too: US study

Water pools in US astronaut's helmet after spacewalk

Korean tech start-ups offer life beyond Samsung

Fast visas and dim sum: Spain seeks to attract Chinese tourists

CYBER WARS
Argentina welcomes first Chinese satellite tracking station outside China

More Astronauts for China

China launches the FY-2 08 meteorological satellite successfully

China's Long March puts satellite in orbit on 200th launch

CYBER WARS
NASA Hopes to Continue Cooperation on ISS Until 2024

Russia to use International Space Station till 2024

Spacewalk to go ahead on Sunday despite helmet leak

NASA preparing to reassemble International Space Station

CYBER WARS
Next Launch of Heavy Angara-5 Rocket Due Next Year

SES Announces Two Launch Agreements With SpaceX

Soyuz-2.1a Rocket Takes Military Satellite to Designated Orbit

Russia's Vostochny Cosmodrome Construction Reaches Home Stretch

CYBER WARS
Planets Can Alter Each Other's Climates over Eons

The mystery of cosmic oceans and dunes

Laser 'ruler' holds promise for hunting exoplanets

Scientists predict earth-like planets around most stars

CYBER WARS
MUOS - a Vital Next Step for Narrowband Satellite Communications

New NASA Space Cowboy Deploys Its 'Lasso'

Moving molecule writes letters

New filter could advance terahertz data transmission




The content herein, unless otherwise known to be public domain, are Copyright 1995-2014 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. Privacy Statement All images and articles appearing on Space Media Network have been edited or digitally altered in some way. Any requests to remove copyright material will be acted upon in a timely and appropriate manner. Any attempt to extort money from Space Media Network will be ignored and reported to Australian Law Enforcement Agencies as a potential case of financial fraud involving the use of a telephonic carriage device or postal service.