New OpenSSL Man-in-the-Middle Flaw Affects All Clients
Trailrunner7 (1100399) writes 'There is a new, remotely exploitable vulnerability in OpenSSL that could enable an attacker to intercept and decrypt traffic between vulnerable clients and servers. The flaw affects all versions of the OpenSSL client and versions 1.0.1 and 1.0.2-beta1 of the server software. The new vulnerability could only be exploited to decrypt traffic between a vulnerable client and a vulnerable server, and the attacker would need to have a man-in-the-middle position on a network in order to do so. That's not an insignificant set of conditions that must be present for a successful attack, but in the current environment, where open wireless networks are everywhere and many users connect to them without a second thought, gaining a MITM position is not an insurmountable hurdle. Researchers who have looked at the vulnerable piece of code say that it appears to have existed, nearly unchanged, in the OpenSSL source since 1998.'
But if you have a man in the middle position, most of those same users would have just clicked "ignore" or typed yes to the "connect anyway" prompt.
"but in the current environment, where open wireless networks are everywhere and many users connect to them without a second thought"
As will always be. Any attempt at security by involving the end user is a recipe for failure.
We're doomed.
Faster! Faster! Faster would be better!
The more of these we find, the more secure OpenSSL will be. I hope we continue to find these kinds of problems and see them fixed. If open source has one strength, it's that when many skilled eyes DO converge on the code it can be tested and fixed far more quickly than a corporation with limited resources and only paid developers can do the same sort of debugging work. The trick is getting the eyes there in the first place.
That's right, it affects all versions that are anywhere close to current.
"When information is power, privacy is freedom" - Jah-Wren Ryel
LibreSSL does not yet have any users.
So it is 100% save!! Yay!! ;-)
You can leave out the "panic". Everyone upgraded. Appropriately. No need for the over-sensationalism.
Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun