Tuesday, September 20, 2011

Hackers break SSL encryption used by millions of sites

ID said (@The Register):

Hackers break SSL encryption used by millions of sites • The Register

At the Ekoparty security conference in Buenos Aires later this week, researchers Thai Duong and Juliano Rizzo plan to demonstrate proof-of-concept code called BEAST, which is short for Browser Exploit Against SSL/TLS. The stealthy piece of JavaScript works with a network sniffer to decrypt encrypted cookies a targeted website uses to grant access to restricted user accounts. The exploit works even against sites that use HSTS, or HTTP Strict Transport Security, which prevents certain pages from loading unless they're protected by SSL.

read more

"Fear of the dark, fear of the dark
I have constant fear that something's
always near
Fear of the dark, fear of the dark
I have a phobia that someone's
always there"

(Iron Maiden - Fear Of The Dark Lyrics)

Or what the hell is it?