New Critical Weaknesses Uncovered In OpenSSL Encryption
This week, new security holes were reportedly uncovered in the same software that was responsible for the insidious “Heartbleed” bug, which may have left as many as 500,000 websites vulnerable to attacks in April.
While the newly discovered bugs are not believed to be as serious as the Heartbleed bug, and could be harder to exploit by hackers, the problem continues to affect OpenSSL – which is used by many tech companies including Google, Facebook, Yahoo and Amazon.
The new bugs were disclosed on Thursday, and these latest vulnerabilities were found as various researchers sought to close Heartbleed. Many of the big firms that used OpenSSL have pledged money to smaller organizations that developed SSL to help improve the bug finding and fixing efforts BBC News reported. While patching the past vulnerability new exploits were discovered.
Security experts have warned that all websites and technology firms that currently utilize OpenSSL should install updates to patch the systems. As with Heartbleed, this could take days or even weeks as firms will have to run tests to ensure that the patches are compatible with their systems.
“They are going to have to patch. This will take some time,” Lee Weiner, senior vice president with cybersecurity software maker Rapid7, told Reuters.
However, other security experts think the problem could be much deeper than is being currently reported. Security researcher Tatsuya Hayashi, who helped find one of the critical bugs this week, told The Guardian that these latest flaws could be “more dangerous than Heartbleed.”
Part of the reason is that the bug is buried so deeply in the code. It may have been introduced in 1998 and yet over the years was missed by both paid and volunteer developers for 16 years. Thus it could be hard to root out. This vulnerability could also affect all PCs and mobile software that rely on OpenSSL prior to the latest version – and is also believed to include the Chrome browser on Android phones, as well as servers running OpenSSL 1.0.1 and the beta version 1.0.2.
“The biggest reason why the bug hasn’t been found for over 16 years is that code reviews were insufficient, especially from experts who had experiences with TLS/SSL implementation,” said security researcher Masahi Kikuchi, who also helped find what is now known as the CCS Injection Vulnerability. “If the reviewers had enough experiences, they should have been verified OpenSSL code in the same way they do their own code. They could have detected the problem.”
Fixing these holes could be far bigger than Heartbleed Nick Percoco, vice president of strategic services from Rapid7 told The Guardian.
“From a remediation standpoint it is actually worse for organizations running OpenSSL on the server side. Heartbleed only affected versions back about two years,” he said. “This issue goes back to the first release of OpenSSL in 1998. That means there were likely many people running version that were not affected by Heartbleed that didn’t patch last time.”
The sky is not falling, however, and it is too early to truly panic was the take of James Lyne, writing for Forbes on Thursday.
“All software has defects and the reporting of such a large group of vulnerabilities is actually reassuring,” Lyne wrote. “During the Heartbleed saga we learned that the team responsible for maintaining this crucial code is surprisingly small, underfunded and the code under-reviewed.”
To that end he suggested: “Make sure your organization has a plan to patch these defects to prevent attackers crashing your critical systems or potentially executing malicious code. In particular pay close attention to web servers but any other system that uses SSL to encrypt information including appliances may have the defect too.”
Source: http://www.redorbit.com/news/technology/1113164474/openssl-encryption-vulnerabilities-060614/
Anyone can join.
Anyone can contribute.
Anyone can become informed about their world.
"United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.
Before It’s News® is a community of individuals who report on what’s going on around them, from all around the world. Anyone can join. Anyone can contribute. Anyone can become informed about their world. "United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.
LION'S MANE PRODUCT
Try Our Lion’s Mane WHOLE MIND Nootropic Blend 60 Capsules
Mushrooms are having a moment. One fabulous fungus in particular, lion’s mane, may help improve memory, depression and anxiety symptoms. They are also an excellent source of nutrients that show promise as a therapy for dementia, and other neurodegenerative diseases. If you’re living with anxiety or depression, you may be curious about all the therapy options out there — including the natural ones.Our Lion’s Mane WHOLE MIND Nootropic Blend has been formulated to utilize the potency of Lion’s mane but also include the benefits of four other Highly Beneficial Mushrooms. Synergistically, they work together to Build your health through improving cognitive function and immunity regardless of your age. Our Nootropic not only improves your Cognitive Function and Activates your Immune System, but it benefits growth of Essential Gut Flora, further enhancing your Vitality.
Our Formula includes: Lion’s Mane Mushrooms which Increase Brain Power through nerve growth, lessen anxiety, reduce depression, and improve concentration. Its an excellent adaptogen, promotes sleep and improves immunity. Shiitake Mushrooms which Fight cancer cells and infectious disease, boost the immune system, promotes brain function, and serves as a source of B vitamins. Maitake Mushrooms which regulate blood sugar levels of diabetics, reduce hypertension and boosts the immune system. Reishi Mushrooms which Fight inflammation, liver disease, fatigue, tumor growth and cancer. They Improve skin disorders and soothes digestive problems, stomach ulcers and leaky gut syndrome. Chaga Mushrooms which have anti-aging effects, boost immune function, improve stamina and athletic performance, even act as a natural aphrodisiac, fighting diabetes and improving liver function. Try Our Lion’s Mane WHOLE MIND Nootropic Blend 60 Capsules Today. Be 100% Satisfied or Receive a Full Money Back Guarantee. Order Yours Today by Following This Link.
