Author Topic: Website security is more broken than we thought  (Read 1257 times)

vorsprung

  • Opposites Attract
    • Audaxing
Website security is more broken than we thought
« on: 20 September, 2011, 04:40:56 pm »
http://www.theregister.co.uk/2011/09/19/beast_exploits_paypal_ssl/

Executive summary:  the special secure method used to make the communication between your PC in your house and a remote server that you might be using for banking, buying things, accessing confidential information etc etc has been beaten and is no longer able to keep these exchanges confidential

If this method gets into widespread use, Internet shopping will become impossible.  Yes there is a fix, it involves updating the browser (Firefox or whatever you run) and also the server out on the Internet.   The fix has not been implemented yet so is likely to be weeks away


Re: Website security is more broken than we thought
« Reply #1 on: 20 September, 2011, 04:54:04 pm »
It's not good, but if you read the details of the exploit you'll find it isn't as doom-mongery as you'd imagine.

It can't be used to decrypt an HTTPS session that occurred in the past. It requires a man-in-the-middle attack to inject some javascript into the page in question so that it is executed whilst browsing that site in order to pad the block-chain cipher functions with enough of the right data that it starts spitting out the cookie data encrypted in a less secure way.

In the 10 minutes it takes to do its magic most people will have completed the transaction and, hopefully, clicked on the 'logout' button, so the cookie for the Paypal session will be useless.
"Yes please" said Squirrel "biscuits are our favourite things."

Riggers

  • Mine's a pipe, er… pint!
Re: Website security is more broken than we thought
« Reply #2 on: 20 September, 2011, 04:58:08 pm »
Greeners? I understood the words '10 minutes', and others like, 'magic', 'useless'… and stuff. But I must confess, unless some of the technical shinanigans has got words in like 'kittens' and 'fluffy bunnies', it goes over my little wooden head.
Certainly never seen cycling south of Sussex

andygates

  • Peroxide Viking
Re: Website security is more broken than we thought
« Reply #3 on: 20 September, 2011, 06:41:57 pm »
That's a clever exploit!
It takes blood and guts to be this cool but I'm still just a cliché.
OpenStreetMap UK & IRL Streetmap & Topo: ravenfamily.org/andyg/maps updates weekly.

Re: Website security is more broken than we thought
« Reply #4 on: 20 September, 2011, 08:00:22 pm »
Greeners? I understood the words '10 minutes', and others like, 'magic', 'useless'… and stuff. But I must confess, unless some of the technical shinanigans has got words in like 'kittens' and 'fluffy bunnies', it goes over my little wooden head.

It's ok, Riggers. Unless you bear some sort of resemblance to the person below, you cannot be expected to make sense of this stuff:



 :demon:


Re: Website security is more broken than we thought
« Reply #5 on: 20 September, 2011, 08:04:51 pm »
Greeners? I understood the words '10 minutes', and others like, 'magic', 'useless'… and stuff. But I must confess, unless some of the technical shinanigans has got words in like 'kittens' and 'fluffy bunnies', it goes over my little wooden head.

It's ok, Riggers. Unless you bear some sort of resemblance to the person below, you cannot be expected to make sense of this stuff:



 :demon:

That's you in 10 years time that is, if you keep audaxing...

Re: Website security is more broken than we thought
« Reply #6 on: 20 September, 2011, 08:20:10 pm »
Damn. You might have something there...better get the hacksaw out and stop the rot

Jaded

  • The Codfather
  • Formerly known as Jaded
Re: Website security is more broken than we thought
« Reply #7 on: 21 September, 2011, 12:10:39 am »
Cool glasses.
It is simpler than it looks.

arabella

  • عربللا
  • onwendeð wyrda gesceaft weoruld under heofonum
Re: Website security is more broken than we thought
« Reply #8 on: 21 September, 2011, 12:11:12 pm »
It can't be used to decrypt an HTTPS session that occurred in the past. It requires a man-in-the-middle attack to inject some javascript into the page in question so that it is executed whilst browsing that site in order to pad the block-chain cipher functions with enough of the right data that it starts spitting out the cookie data encrypted in a less secure way.

In the 10 minutes it takes to do its magic most people will have completed the transaction and, hopefully, clicked on the 'logout' button, so the cookie for the Paypal session will be useless.
It can only happen while you are actually on line with paypal.
To happen, someone/thing needs to 'see' you are doing a transaction, then alter the page you are doing to tweak 'stuff' in order to get at the data required.
Unless you are still on line at that point you are safe.

Summary: don't take any longer than you need.
Any fool can admire a mountain.  It takes real discernment to appreciate the fens.

sas

  • Penguin power
    • My Flickr Photos
Re: Website security is more broken than we thought
« Reply #9 on: 21 September, 2011, 12:56:04 pm »
Summary: don't take any longer than you need.

That's not practical for Facebook or GMail though.
I am nothing and should be everything