HomeSecurityTests confirm that Heartbleed bug can compromise...

Tests confirm Heartbleed bug can compromise server private key

heartbleed1-676x450

Four researchers working separately have shown that a server's private encryption key can be revealed using the Heartbleed, an attack that is considered feasible but unconfirmed.

The findings come shortly after a challenge created by CloudFlare, a company that provides security solutions for website administrators.

CloudFlare asked the security community whether the flaw in OpenSSL, which was disclosed last week, could be used to obtain the private key used to create an encrypted channel between users and websites, known as SSL/TLS (Secure Sockets Layer/Transport Security Layer). The private key is part of the security certificate that verifies that a client computer is not connecting to a fake website. Browsers indicate a secure connection with a padlock and show a warning if the certificate is not valid.

More: https://www.pcworld.com/article/2143080/tests-confirm-heartbleed-bug-can-expose-servers-private-key.html

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS