• Home
  • About Us
  • Contact
  • Advertise
  • Awards
  • Privacy Policy
  • Twitter
  • Facebook
  • RSS
TheDomains.com

Google Discloses A Vulnerability in SSL 3.0

October 14, 2014 by Raymond Hackney

google

Google reported via their online security blog, that there is a vulnerability in the design of SSL Version 3.0. Apparently usage is ubiquitous as most browsers support SSL 3.0. They have recommended a work around to the problem.

From the article:

Today we are publishing details of a vulnerability in the design of SSL version 3.0. This vulnerability allows the plaintext of secure connections to be calculated by a network attacker. I discovered this issue in collaboration with Thai Duong and Krzysztof Kotowicz (also Googlers).

SSL 3.0 is nearly 15 years old, but support for it remains widespread. Most importantly, nearly all browsers support it and, in order to work around bugs in HTTPS servers, browsers will retry failed connections with older protocol versions, including SSL 3.0. Because a network attacker can cause connection failures, they can trigger the use of SSL 3.0 and then exploit this issue.

Disabling SSL 3.0 support, or CBC-mode ciphers with SSL 3.0, is sufficient to mitigate this issue, but presents significant compatibility problems, even today. Therefore our recommended response is to support TLS_FALLBACK_SCSV. This is a mechanism that solves the problems caused by retrying failed connections and thus prevents attackers from inducing browsers to use SSL 3.0. It also prevents downgrades from TLS 1.2 to 1.1 or 1.0 and so may help prevent future attacks.

Google Chrome and our servers have supported TLS_FALLBACK_SCSV since February and thus we have good evidence that it can be used without compatibility problems. Additionally, Google Chrome will begin testing changes today that disable the fallback to SSL 3.0. This change will break some sites and those sites will need to be updated quickly.

Filed Under: Google

« .XYZ Crosses 600,000 Domain Registrations and .Club is gaining ground for the number two spot
World Wrestling Entertainment Wins Control Of WWE.org »


Recent Articles

  • Dynadot increasing auction deposits
  • Rick Schwartz AiReviews.com deal sets off a flurry of AiReview related domain registrations
  • Sedo weekly domain name sales led by Diffs.com

Recent Comments

  • Raymond Hackney on Rick Schwartz weighs in on the second Coinbook.com auction
  • James K. on Rick Schwartz weighs in on the second Coinbook.com auction
  • Jose on Rick Schwartz weighs in on the second Coinbook.com auction
  • Rick Schwartz on James Booth is a bit miffed by those shitting on the .ai extension
  • brad on James Booth is a bit miffed by those shitting on the .ai extension

Categories

Archives

Copyright ©2025 TheDomains.com