An updated version of the Sophos Web Appliance managed to bring down thousands of users' computers and take a global company's Australian call center offline for two days. The reason for the disaster was that the security company revoked the SSL 3.0 encryption algorithm used in Citrix Receiver.
The British security firm attempted to fix four non-critical SSL 3.0 issues with the release of update 4.0.2.3 last week.
However, this update was the cause of the disaster that followed, as it was not compatible with recent versions of Citrix Receiver. The new Citrix had been updated to fend off POODLE attacks.
The Australian company, as mentioned above, went offline for two days – and continues to experience outages – after the update prevented operators from accessing a portal required for sending critical listings.
The Australian company's administrator said Sophos did not warn them about the SSL 3.0 recall and it took them 24 hours to respond to a support email, according to El Reg.
The Sophos update should have been planned and coordinated in advance, according to the administrator.
