Skip to main content

Is SSL safe?

posted onMarch 24, 2003
by hitbsecnews

Source: Security Focus

Czech security researchers this week claimed to have uncovered weaknesses in SSL that might permit crackers to decypher transmissions over supposedly secure links.

However, independent cryptography experts, who are studying a paper from Czech security outfit ICZ, are yet to verify the risk is real and as serious as ICZ suggests - so the research needs to be treated with caution.

A press release issued on behalf of Czech cryptologists Vlastimil Klíma and Tomá? Rosa, both of ICZ, and Ondrej Pokorný, paints a picture of severe problems with the SSL protocol. It states:

"The weakness identified by the cryptologists makes it possible to attack the SSL/TLS (Secure Sockets Layer and Transport Layer Security) protocols used as a cryptographic protection of a majority of electronic transactions, such as on-line purchases and e-banking, and, in some cases, a secured transmission of e-mails as well.

"An attack on these protocols, as described by the team of Czech cryptologists, can break through the protection completely and decrypt protected communication. This means for clients using applications relying on SSL/TLS protocols that an attacker is able to retrieve their credit card numbers, sensitive information about their bank accounts and misuse confidential data from their e-mails."

Source

Tags

Encryption

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th