PRESS RELEASE
Cybercrime Directorate updates on the identification of a security vulnerability in the SSL-3 encryption protocol
The Hellenic Police's Cybercrime Directorate informs internet users about the identification of a serious vulnerability in the security of the SSL-3 encryption protocol, which was named Poodle (Padding Oracle On Downloaded Legacy Encryption).
Specifically, the SSL-3 encryption protocol is widely used for encrypted communication between a browser and a server. Although the SSL 3.0 protocol is about fifteen (15) years old, it is still widely used in most browsers and as a backup on servers if modern encryption protocols fail to connect.
Specifically, this vulnerability allows a malicious user (cracker) to carry out attacks, which are called “man-in-the-middle” and bypass the encrypted communication between a browser (browser) and a server (server) by collecting sensitive personal data, as well as connection cookies. With this information, (the malicious user) can then gain access to users' online accounts.
Additionally, the most significant problem arising from the Poodle vulnerability is that it forces a downgrade to SSL 3.0, making even a system that uses a superior encryption method, such as the TLS (Transport Layer Security) protocol, vulnerable.
It is noted that the conditions in which a malicious user (cracker) can exploit the above vulnerability with relative ease are on public networks (such as public WiFi).
Internet users are urged to take the following minimum protection measures to avoid being affected by the above vulnerability:
- If their browser supports it, disable the SSL 3.0 protocol or use tools that support TLS_FALLBACK_SCSV (Transport Layer Security Signaling Cipher Suite Value), which will prevent downgrade attacks.
- Always update your browser to the latest official version.
- Be particularly careful when using public networks (public WiFi).

