Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

SSL Web Security Protocol Compromised by Researchers

Add as a preferred source on Google
Ethernet connector
Image used with permission by copyright holder

Two researchers with PhoneFactor, a company that offers two-factor authentication services, say that thay have uncovered a serious vulnerability in SSL (Secure Sockets Layer), a fundamental online security technology that’s widely used to safeguard ecommerce transactions and other sensitive data. The flaw, in theory, can enable attackers to insert themselves into a secured online transaction as a “man in the middle,” able to view all data moving back and forth between two parties—and alter the data stream and issue commands—on what the users believe is a secured connections.

The researchers, Marsh Ray and Steve Dispensa, found the error in August 2009 and reported it to a group of impacted vendors and standards committees without publicly disclosing the problem. PhoneFactor had planned to hold off on disclosing the vulnerability until early 2010 in order to give vendors time to patch their SSL software and deploy fixed versions to their customers, but another research discovered the bug independently and posted it to an IETF mailing list on November 4.

Recommended Videos

“Because this is a protocol vulnerability, and not merely an implementation flaw, the impacts are far-reaching,” said PhoneFactor CTO Steve Dispensa, in a statement. “All SSL libraries will need to be patched, and most client and server applications will, at a minimum, need to include new copies of SSL libraries in their products. Most users will eventually need to update any software that uses SSL.”

SSL is widely used to secure transmissions for a variety of applications, from ecommerce and online banking, Web-based management of almost any sort of customer account, as well as non-Web applications like database servers, email, and enterprise systems.

The new vulnerability is not the first to hit SSL in recent months: at the Black Hat security conference in Las Vegas security researchers Mike Zusman and Alex Sotirov demonstrated a browser design flaw that enabled man-in-the-middle attacks on SSL connections. Other recent attacks on SSL have focused on clandestinely shifting traffic from SSL_protected https:// connections to unsecured http:// links.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
OpenAI is investigating more incidents of AI agents going rogue days after hack
OpenAI logo on Microsoft surface

It appears that the "AI agents going rogue" tale has more to it than what AI giants have revealed publicly so far. Merely days after OpenAI announced that its AI agents went rogue and hacked Hugging Face, Anthropic dropped a similar bombshell. Soon, it was discovered that not just one, but multiple services were compromised. Well, it seems there are even more layers to it.

Reuters reports that OpenAI has found more incidents of AI agents escaping their software containment environment during research. Citing sources with knowledge of the incident, the outlet notes that the AI agents didn't go beyond OpenAI's software environment and affect any external service.

Read more
AI is finding Apple security flaws faster than Apple can sort through them
Apple has limited how many bug reports researchers can keep open as AI tools produce both genuine Mac vulnerabilities and a flood of questionable submissions
Lighting, Architecture, Building

Apple has capped the number of security reports researchers can keep open at once after AI bug hunting put its review process under pressure, according to the Financial Times.

Some submissions describe hallucinated or purely theoretical risks. Others uncover vulnerabilities serious enough to require patches. Bynario told the FT that it found more than 50 possible macOS flaws in three weeks, including a privilege-escalation chain that could give an attacker full control of a Mac.

Read more
Anthropic is paying $1.5 billion over pirated books, but it can still legally cut up purchased ones
The settlement addressed unauthorized ebook downloads, not the destructive scanning of lawfully bought physical copies, a distinction now alarming booksellers
Book, Publication, Indoors

A federal judge has approved Anthropic’s $1.5 billion settlement over nearly half a million pirated books. The same litigation also protected a more physical method of feeding its AI systems. Anthropic bought print books, removed their bindings, scanned every page and destroyed the originals.

The legal divide came down to acquisition. The settlement covers books downloaded from LibGen and PiLiMi, while the court treated Anthropic’s one-for-one conversion of purchased books into private digital files as fair use. Training AI models on lawfully acquired material was also considered transformative.

Read more