Broken Web Browser Security

According to “Security Now” (www.grc.com), last month a hacker who goes by the moniker of Moxie Marlinspike, gave a presentation titled “New Tricks for Defeating SSL in Practice” at the Black Hat conference in DC.  While SSL encryption is a very secure protocol, it has now been shown possible to spoof a secure site forcing a redirected connection with SSL encryption entact.  Once redirected the hacker can steal any secure information you enter into the fake web form.  You may never know you were dupped. 

Most Browsers are using a shared library called CryptoAPI which Internet Explorer, Safari on Windows, and Chrome all use.  They all just assume the underlying framework in Windows reliable.  They’re all using it and as a consequence, as of today they’re all vulnerable. 

Essentially at the moment a Windows user cannot trust any Windows browser other than Firefox.  The Firefox guys fixed this within their browser.  They took responsibility away from the underlying Windows platform and fixed it themselves within days. 

Apple did fix it in OS X immediately, but hasn’t done so on Safari under Windows as its not their fault.  This is a Windows problem.  The problem is that it makes all browsers except Firefox completely untrustworthy for making secure SSL connections until Microsoft finally fixes it.   I recommend using Firefox only, until they do.

About Kevin

I am a faithful husband of one bride, father of five precious children, grandfather of seven wonderful grandchildren, and a follower of Jesus Christ. I have much to learn as I study to deepen my covenant relationship with the God of the Bible and with my family, through my obedient dependence on the creator of all nature and life. I am a Process Engineer by trade, self taught IT Technician, and a hunting enthusiast by virtue of my rural upbringing. I am an vehicle accident survivor (of near death), saved by the amputation of my right leg at age 16. Serving others thru creator endowed interests is my true joy.
This entry was posted in Tech Insights. Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *