Slashdot Mirror


New OpenSSL Man-in-the-Middle Flaw Affects All Clients

Trailrunner7 (1100399) writes 'There is a new, remotely exploitable vulnerability in OpenSSL that could enable an attacker to intercept and decrypt traffic between vulnerable clients and servers. The flaw affects all versions of the OpenSSL client and versions 1.0.1 and 1.0.2-beta1 of the server software. The new vulnerability could only be exploited to decrypt traffic between a vulnerable client and a vulnerable server, and the attacker would need to have a man-in-the-middle position on a network in order to do so. That's not an insignificant set of conditions that must be present for a successful attack, but in the current environment, where open wireless networks are everywhere and many users connect to them without a second thought, gaining a MITM position is not an insurmountable hurdle. Researchers who have looked at the vulnerable piece of code say that it appears to have existed, nearly unchanged, in the OpenSSL source since 1998.'

13 of 217 comments (clear)

  1. Neat by Anrego · · Score: 4, Insightful

    But if you have a man in the middle position, most of those same users would have just clicked "ignore" or typed yes to the "connect anyway" prompt.

  2. Re:Key phrase of vulnerability : by ColdWetDog · · Score: 5, Insightful

    "but in the current environment, where open wireless networks are everywhere and many users connect to them without a second thought"

    As will always be. Any attempt at security by involving the end user is a recipe for failure.

    We're doomed.

    --
    Faster! Faster! Faster would be better!
  3. This is awesome by nctritech · · Score: 4, Insightful

    The more of these we find, the more secure OpenSSL will be. I hope we continue to find these kinds of problems and see them fixed. If open source has one strength, it's that when many skilled eyes DO converge on the code it can be tested and fixed far more quickly than a corporation with limited resources and only paid developers can do the same sort of debugging work. The trick is getting the eyes there in the first place.

    1. Re:This is awesome by Anonymous Coward · · Score: 5, Informative

      OpenSSL design is fundamentally flawed. Bug fixes will probably introduce more bugs in many cases.

      Well, the LibreSSL project is ripping out much of the code and rebuilding it: http://www.libressl.org/

      I mean, OpenSSL will use your actual private key as a source of entropy. How messed up is that?

      Ummm, your private key should be randomly generated, otherwise public key encryption doesn't work too well.

      But your private key doesn't change, so that isn't a good thing to do. Fixing the entropy is one of the many things LibreSSL is doing: http://www.openbsd.org/papers/bsdcan14-libressl/mgp00016.html

    2. Re:This is awesome by iamgnat · · Score: 5, Insightful

      open source has one strength, it's that when many skilled eyes DO converge on the code it can be tested and fixed far more quickly

      Did you even read the summary? They believe that this flaw has existed since 1998. You have a very strange definition of "quickly" if 16 years falls into that category.

      I'm all for OSS, but people like you that continue to trot out this tripe aren't helping it. The benefit isn't that there all these mythical "skilled eyes" looking at the code, it's that you can look at the code.

    3. Re:This is awesome by evilviper · · Score: 4, Insightful

      If open source is so great, this flaw wouldn't have been around this long, would it?

      Closed source software is far worse, you just don't hear about it.

      --
      Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
    4. Re:This is awesome by Dcnjoe60 · · Score: 5, Insightful

      I agree that 16 years for a fundamental flaw like this is bad, but how can you possibly know that closed source is no worse (or no better) than this? Closed-source software vendors are usually not very open about these problems.

      I agree 100%. The only reason this flaw is known is because the source code was available to review. Obviously, it would have been better if this were reviewed and caught sooner, but that ignores the fact that it was only caught because the source code was available. That seems to be a big plus.

      Also what is interesting is that even though the flaw has been there for 16 years, there are no known exploits of it. That would seem to dismiss the notion that open source security software is problematic because bad people can find exploits.

      Of course another explanation is that the flaw isn't any such thing and was intentional and because it was open source, certain government agencies will now lose the ability to exploit it.

      Regardless of how you look at it, it seems to be an advantage to open source.

    5. Re:This is awesome by nctritech · · Score: 5, Insightful

      If you've been following OpenSSL Heartbleed coverage, you know that the project has only had one full-time developer working on it. Since Heartbleed (a recent discovery, you'll recall) they've discovered more holes to close such as this one. I'd call less than two months since more eyes started staring at OpenSSL "quickly."

    6. Re:This is awesome by g1zmo · · Score: 4, Funny

      Literally no one has ever said that.

      --
      I have found there are just two ways to go.
      It all comes down to livin' fast or dyin' slow.
      -REK, Jr.
  4. Re:Versions by GameboyRMH · · Score: 4, Informative

    That's right, it affects all versions that are anywhere close to current.

    --
    "When information is power, privacy is freedom" - Jah-Wren Ryel
  5. Re: Key phrase of vulnerability : by Anonymous Coward · · Score: 5, Funny

    LibreSSL does not yet have any users.

  6. Re: Key phrase of vulnerability : by aix+tom · · Score: 5, Funny

    So it is 100% save!! Yay!! ;-)

  7. Re:Versions by Zero__Kelvin · · Score: 4, Insightful

    "especially after everyone panic-upgraded after heartbleed."

    You can leave out the "panic". Everyone upgraded. Appropriately. No need for the over-sensationalism.

    --
    Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun