HomeSecurityLogJam: Collaboration of large companies to tackle it

LogJam: Collaboration of large companies to tackle it

LogJam: Major companies collaborate to address it – Major technology companies are collaborating to develop a patch to address a bug observed in an encryption algorithm in web browsers that makes illegal tracking possible.

LogJam: Collaboration of large companies to tackle it

However, the updates that will be made available to fix the bug may cause many websites to stop working.

The "LogJam attack", as experts have named the bug, was discovered by Microsoft researchers, who estimate that approximately 8% of the 1 million most well-protected websites are vulnerable to potential attacks due to this bug.

Also, some email services that use the Transport Layer Security (TLS) encryption protocol are at risk of being attacked until their systems are updated.

As the British news network BBC reports in an article, LogJam is the "legacy" left by the US in the 1990s with the restrictions it had imposed on the export of encryption tools. These restrictions degraded the complexity of the secret encryption codes that could be produced.

These restrictions have since been relaxed, but researchers say an unintended consequence of this is that the Diffie-Hellman Key Exchange (DHKE) cryptographic algorithm is vulnerable to man-in-the-middle attacks. DHKE was one of the first techniques developed to allow two or more parties to generate and share encryption keys.

What the researchers discovered was that by bypassing communications, attackers are able to use a 512-bit encryption key instead of a more complex one.

However, the patch that the Internet browser companies agreed to develop will be able to block encryption keys of 512-bits or less.

"The solution is relatively simple, but unfortunately some older web servers may not be able to initiate a secure communication with the upgraded web browsers, as they only support the older, weaker and shorter key lengths," said Professor Alan Woodward of the University of Surrey in Britain. "Browsers could be easily upgraded and servers could be easily reconfigured, and that's not a bad thing when you consider that in a different scenario the 'secure communication' could potentially be illegally monitored by a hacker," he added.

Mozilla, the company that developed the Firefox browser, announced that its new software that will fix the LogJam will be available "in the coming days."

An internet security expert said that Internet users should not worry about falling victim to an attack like LogJam, but stressed that public services and organizations should keep their "eyes open.".

 

 

Source: nooz

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS