HomeSecurityCritical OpenSSL flaw leaves two-thirds of the Web vulnerable to...

Critical OpenSSL flaw leaves two-thirds of the Web vulnerable to eavesdropping

Man_in_the_middle_attack-640x454

Researchers have discovered a critically important flaw in library encryption software, and it is estimated that two-thirds of Web servers use it to identify themselves to end users and prevent the interception of passwords, bank statements and other sensitive data.

The warning about the bug in OpenSSL coincided with the release of version 1.0.1g of the open-source program, which is the default cryptography library used in Apache and nginx web server applications, as well as a wide variety of operating systems and email and even instant-messaging applications. The bug, which has been present in versions of OpenSSL for more than two years, could make it possible for users to recover the private encryption key at the heart of digital certificates used to authenticate to servers on the Internet and encrypt data traveling between them. The attacks leave no traces in the servers' logs, so there is no way to know whether the bug has been actively exploited. Still, the risk is great, as the ability to reveal keys, passwords, and other information could be used in future attacks.

You can see more details about the error here.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS