HomeSecurityChrome 39 will have SSL 3.0 disabled by default, the...

Chrome 39 will have SSL 3.0 disabled by default, Chrome 40 removes it completely

Chrome-39-compressedUsers using the SSL 3.0 protocol will no longer be able to use it through Google Chrome in version 40.

This change comes after the POODLE (Padding Oracle on Downgraded Legacy Encryption) attack that downgrades an HTTPS connection such as TLS 1.2 to the faulty SSL 3.0, which allows sensitive information to be extracted.

Exploitation of SSL 3.0 is achieved by using network communication errors, which will make the server assume that a newer version of the encryption protocol is being used, which is not supported by the client, resulting in it attempting to use less secure versions of the protocol.

Adam Langley, a security engineer at Google, posted an update on Thursday saying that the next version of Google Chrome will have the option to enable SSL 3.0 (which will be disabled by default). As a result, some servers may stop working, but websites that only support SSL 3.0 will continue to work until the next stable version of Chrome is released.

In Chrome 39, whenever an HTTPS connection using SSL 3.0 occurs, a yellow padlock notification appears in the address bar, signaling the potential risk of confidential data being leaked. All websites should be updated to accept TLS 1.0 as the newest protocol for encrypted connections.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS