uvst – Rufo Guerreschi https://old.rufoguerreschi.com "Love of True Self and Love of Others Coincide. Love is What We Are" Tue, 08 Apr 2014 13:21:32 +0000 en-US hourly 1 https://wordpress.org/?v=6.0.9 Critical crypto bug in OpenSSL opens two-thirds of the Web to eavesdropping | Ars Technica https://old.rufoguerreschi.com/2014/04/08/critical-crypto-bug-in-openssl-opens-two-thirds-of-the-web-to-eavesdropping-ars-technica/ https://old.rufoguerreschi.com/2014/04/08/critical-crypto-bug-in-openssl-opens-two-thirds-of-the-web-to-eavesdropping-ars-technica/#respond Tue, 08 Apr 2014 13:21:32 +0000 http://www.rufoguerreschi.com/2014/04/08/critical-crypto-bug-in-openssl-opens-two-thirds-of-the-web-to-eavesdropping-ars-technica/ Continue reading Critical crypto bug in OpenSSL opens two-thirds of the Web to eavesdropping | Ars Technica ]]> http://arstechnica.com/security/2014/04/critical-crypto-bug-in-openssl-opens-two-thirds-of-the-web-to-eavesdropping/

The researchers, who work at Google and software security firm Codenomicon, said even after vulnerable websites install the OpenSSL patch, they may still remain vulnerable to attacks. The risk stems from the possibility that attackers already exploited the vulnerability to recover the private key of the digital certificate, passwords used to administer the sites, or authentication cookies and similar credentials used to validate users to restricted parts of a website. Fully recovering from the two-year-long vulnerability may also require revoking any exposed keys, reissuing new keys, and invalidating all session keys and session cookies. Members of the Tor anonymity project have a brief write-up of the bug here, and a this analysis provides useful technical details

]]>
https://old.rufoguerreschi.com/2014/04/08/critical-crypto-bug-in-openssl-opens-two-thirds-of-the-web-to-eavesdropping-ars-technica/feed/ 0