News

SSL Bug Lets People Impersonate Anyone

So you’re browsing online, through Facebook, Ebay and even your bank and you notice that padlock at the start of your address bar. You see that symbol and you think, that means I’m secure. I’m safe and I can browse and send information without a worry. Seems like that might be a mistake according to a new bug report.

SSL is the system in which websites can be verified, this means you can be certain that the website you’re sending information to is actually the website you want and not someone pretending. It also means that you have to use a standard of encryption when communicating information across the web. OpenSSL is a standard used by a variety of websites in order to offer some security and reassurance to its users, and sadly is publicly available meaning that users are free to view and edit the code as they see fit.

From the log that’s available it appears that the code responsible for the problem was added all the way back in January, however, it was only released to the publicly used version last month. With this problem, it would be possible for fake websites to change and “appear” as if they were the legitimate version and due to how the system works, fake websites would also be able to provide “certificates” for other websites.

While it was in the public version it didn’t make its way into the mainstream versions used by a lot of people, meaning that it has since been removed and the damage limited (if there is any at all). This is in contrast to the Heartbleed virus that resided in OpenSSL for almost two whole years before being discovered.

Thank you ArsTechnica for the information.

Image courtesy of the BBC.

Gareth Andrews

Disqus Comments Loading...

Recent Posts

Fortnite Main Battle Royal Mode Was Thought up in the Back of an Uber

No matter who you are or where you are it's pretty sure thing that you've…

15 hours ago

Philips Evnia 42″ 3840×2160 OLED 138Hz 0.1ms A-Sync HDR Widescreen Gaming Monitor

Low input lag reduces time delay between devices to monitor SmartImage game mode optimised for…

16 hours ago

Alphacool Apex Stealth Metal fan 2000rpm Matte Black

High-quality, elegant as well as timeless design and technical innovation - these are the features…

16 hours ago

NZXT T120 RGB Performance 120mm CPU Cooler

Aluminum heat pipe cover discreetly hides copper piping 4 conductive copper heat pipes with Direct…

16 hours ago

ASUS ROG Ryujin III 240 ARGB Performance AIO CPU Liquid Cooler

The customizable ARGB fans snap together with a magnetic connector that links the fans and…

16 hours ago

Varmilo VEA88 CMYK Gaming Keyboard, MX-Red, White-LED

TKL mechanical keyboard with 88 keys in a UK ISO layout V-silk PBT keycaps with…

16 hours ago