Hackers break SSL encryption used by millions of sites

Gamingphreek

Lifer
Mar 31, 2003
11,679
0
81
As of right now, only Opera 10 and Internet Explorer 8 and above support TLS 1.1 and 1.2.

Firefox and Chrome support 1.0.

Safari (Apple's security is pitiful) simply says it supports TLS... doesn't say which version.
 

dawks

Diamond Member
Oct 9, 1999
5,071
2
81
Should be noted this is a "man-in-the-middle" attack. Thus a hacker would need control of some portion of the network between you and the server your connecting to. Pretty rare occurrence.
 

MtnMan

Diamond Member
Jul 27, 2004
9,365
8,705
136
Should be noted this is a "man-in-the-middle" attack. Thus a hacker would need control of some portion of the network between you and the server your connecting to. Pretty rare occurrence.
:thumbsup: And they have to be in the right place at the right time, making their chances small.

Additionally XP does not provide support for TLS 1.1
Many websites do not yet support TLS 1.1

If there is a caution in this........... stay off wireless connections you don't trust.
 
Last edited:

General Kenobi

Senior member
Sep 29, 2011
310
0
0
Yeah, you'll be safe as long as you retain full control of your home network.
 
Last edited:

Gamingphreek

Lifer
Mar 31, 2003
11,679
0
81
:thumbsup: And they have to be in the right place at the right time, making their chances small.

Additionally XP does not provide support for TLS 1.1
Many websites do not yet support TLS 1.1

If there is a caution in this........... stay off wireless connections you don't trust.

The OS does not determine whether SSL is supported.

Additionally you don't necessarily need control over a portion of the network. You can intercept the packets and relay them on towards the destination.

-Kevin
 

MtnMan

Diamond Member
Jul 27, 2004
9,365
8,705
136
W7
W20110929-PW-X7-TLS.jpg



XP
W20110929-PW-XP-TLS.jpg


:whiste:
 

Gamingphreek

Lifer
Mar 31, 2003
11,679
0
81
Those settings only govern Internet Explorer and are listed there because Internet Explorer is integrated into the Windows Shell. The OS has no idea about SSL/TLS.
 

Fox5

Diamond Member
Jan 31, 2005
5,957
7
81
Should be noted this is a "man-in-the-middle" attack. Thus a hacker would need control of some portion of the network between you and the server your connecting to. Pretty rare occurrence.

Unless it's your government, ISP, or employer trying to spy on you. China also demonstrated the ability to hijack network traffic about a year or two ago.
Of course, if the group you rely on for your Internet connection is trying to MITM you, there really isn't much you can do. In theory, you could set up an IPSec connection between yourself and the destination, but it's not like you can do that with Amazon or whomever you want.

TLS1.0 has been known to be insecure for (at least) nearly 2 years. A lot of Linux vendors started turning it off in their distros once it was provably exploitable.
 

Wangstang

Member
Oct 30, 2005
190
0
0
While traveling last week, I noticed several wireless network connections were available in my hotel. I couldn't help but think that in a setting like a hotel would be a target rich environment for hackers exploiting this vulnerablity. With so many naive to internet security folks in the US who do online financial transactions/look at bank info on various electronic devices, I can see them just clicking the "connect to available wireless network" option without thinking even once about the risk involved.

Wes
 

WildHorse

Diamond Member
Jun 29, 2003
5,006
0
0
SSL is easily cracked, so HTTPS ought not be relied upon for any measure of security. Finding these "how-to's" mostly ON YOUTUBE took me only few seconds, practically without even trying, and I didn't even search google, which MAKES THE POINT: ANYBODY CAN DO IT, the "how to" is all over YouTube, SO DO NOT TRUST HTTPS for any real security:

Cracking SSH Logins
Ssl And The Future Of Authenticity (Blackhat 2011)
SSL vs. The Universe | Cracking an SSL Certificate
Hack Tutorial: Sniffing SSL Passwords
Download hacking tools All In One pack with full instruction
SSL Hacking
Hacking and decrypting SSL
How to: Snifff SSL / HTTPS (sslstrip)
Sniffing https with ettercap
Cracking A Simple Crackme

(p.s. How To Hack Into Someones Webcam Updated Instructions) [so maybe put tape over the camera staring at you on your laptop?]
 

Gamingphreek

Lifer
Mar 31, 2003
11,679
0
81
You are vastly oversimplifying the process. A bunch of Youtube videos doesn't mean it is easy...

-GP