Hacker reveals SSL encryption bypass
The online security on secure websites such as those involved in internet banking has been thrown into question by an internet researcher who claims that the sites can be compromised.
Moxie Marlinspike has tabled at the Black Hat conference in the US methods he says can bypass SSL encryption used by websites displaying the padlock mark, which denotes that the internet security of the said websites is foolproof.
The independent hacker revealed in a presentation at the Washington conference that there were several ways in which the encryption's
"chain of trust" could be compromised.
In a revelation that is likely to cause an internet security nightmare for many banking institutions and their security experts, the hacker also revealed the existence of a free software tool called "SSL Strip".
This software can be used against a network as well as a man in the middle attack targetting SSL connections.
Websense Security Labs recently stated that 77 per cent of infected websites are legitimate sites that have been compromised.
Powerful protection against malicious virus infections. Visit www.pctools.com to upgrade your protection
Related News
- July 30, 2009 - Spammers translating messages to cause global web security issues
- July 30, 2009 - Web users 'should be cautious of fake anti-virus programmes
- July 29, 2009 - Microsoft launches online security patch
- July 28, 2009 - Students 'putting parents at risk of ID theft'
- July 24, 2009 - New online threats to be debuted
PC Tools Spyware Doctor™ with AntiVirus
PC Tools™ Internet Security



