After Heartbleed came Logjam. Those in tech will remember the Heartbleed vulnerability, which came to remind us that security is not a given on the Internet. While IT is still trying to forget about the SSL vulnerability that forced them to run and not reach, researchers have discovered another major flaw in SSL called “Logjam” or in Greek “dead end” and it affects a number of fundamental Web protocols.
The bug affects an algorithm called “Diffie-Hellman key exchange” which allows protocols like HTTPS, SSH, IPsec, SMTPS to exchange a shared key to establish a secure connection.
Cryptanalyst Matthew Green from Johns Hopkins University discovered several weaknesses in the algorithm and published a technical paper detailing them. You can read the academic paper here (PDF).
The attack allows man-in-the-middle by downgrading the security of connections to a lower level of encryption (512 bits) which can be read with relative ease.
This means that groups with large amounts of computing power at their disposal, such as the NSA, could break even stronger encryption (768-bit or even 1024-bit) using the algorithm.
The study estimates that up to 8.4% of the top 1,000,000 websites are vulnerable, along with a huge number of email services and other systems.
You can check if your browser is vulnerable here. At the time of writing, all major browsers are still open to attack. 
Google has already developing a patch that will increase the SSL requirement in Chrome to 1024 bits.
Those of you who are server administrators should immediately follow the instructions (link at the end of the post) that have been issued to protect your environment from the Logjam bug.
For everyone else, be careful not to surf unknown websites, or websites recommended to you by strangers.
All known browsers are affected by this vulnerability.
