Hello,

We noticed you're browsing in private or incognito mode.

To continue reading this article, please exit incognito mode or log in.

Not an Insider? Subscribe now for unlimited access to online articles.

A View from Erica Naone

New Flaws Revealed In A Creaking Internet

Researchers at Black Hat reveal flaws in the infrastructure designed to keep sensitive information secure.

  • July 31, 2009

In separate presentations at the Black Hat computer security conference in Las Vegas this week, two researchers revealed flaws with the system that protects credit card and password transactions online.

The Secure Socket Layer (SSL) protocol implements the padlock that appears in a browser’s address bar–an outward symbol that the underlying communication between browser and server is secure and that the Web page is what it claims to be.

Dan Kaminsky and Moxie Marlinspike separately demonstrated a number of problems with SSL, some immediate and some that could become an issue within the next 18 months. Some of these issues are caused by inconsistencies in how SSL is implemented in the browser compared with how SSL is implemented by the certificate authorities that form the backbone of the system.

Rumblings about this infrastructure have been going on for some time–late last year, researchers Alexander Sotirov and Marc Stevens showed that an outdated algorithm could undermine the system. Later, Marlinspike released a tool that an attacker could use to capture supposedly secure information.

Later today at Black Hat, Sotirov plans to show further problems with “extended validation” SSL certificates, which are supposed to provide a more secure version of the system.

Last year at Black Hat, Kaminsky revealed a major flaw affecting a vital piece of Internet infrastructure that matches website addresses to the servers that hosts their pages. Kaminsky said in a press conference yesterday that the “creaking” of the SSL infrastructure is a sign that it’s time to look for a new solution. He suggests DNSSEC, a protocol meant to secure the system for looking up website addresses. Kaminsky believes that it could be designed to guarantee a page’s identity at the same time it links a user to a requested server. Other researchers, however, including some of Kaminsky’s collaborators, don’t agree that DNSSEC is the solution, and think there are ways to bolster SSL without discarding it.

Regardless of how people decide to fix the problems revealed at Black Hat, the takeaway is that much of the infrastructure supporting the Internet is straining with the weight of unintended responsibility.

Want to go ad free? No ad blockers needed.

Become an Insider
Already an Insider? Log in.
Want more award-winning journalism? Subscribe and become an Insider.
  • Insider Plus {! insider.prices.plus !}* Best Value

    {! insider.display.menuOptionsLabel !}

    Everything included in Insider Basic, plus the digital magazine, extensive archive, ad-free web experience, and discounts to partner offerings and MIT Technology Review events.

    See details+

    Print + Digital Magazine (6 bi-monthly issues)

    Unlimited online access including all articles, multimedia, and more

    The Download newsletter with top tech stories delivered daily to your inbox

    Technology Review PDF magazine archive, including articles, images, and covers dating back to 1899

    10% Discount to MIT Technology Review events and MIT Press

    Ad-free website experience

  • Insider Basic {! insider.prices.basic !}*

    {! insider.display.menuOptionsLabel !}

    Six issues of our award winning print magazine, unlimited online access plus The Download with the top tech stories delivered daily to your inbox.

    See details+

    Print Magazine (6 bi-monthly issues)

    Unlimited online access including all articles, multimedia, and more

    The Download newsletter with top tech stories delivered daily to your inbox

  • Insider Online Only {! insider.prices.online !}*

    {! insider.display.menuOptionsLabel !}

    Unlimited online access including articles and video, plus The Download with the top tech stories delivered daily to your inbox.

    See details+

    Unlimited online access including all articles, multimedia, and more

    The Download newsletter with top tech stories delivered daily to your inbox

/3
You've read of three free articles this month. for unlimited online access. You've read of three free articles this month. for unlimited online access. This is your last free article this month. for unlimited online access. You've read all your free articles this month. for unlimited online access. You've read of three free articles this month. for more, or for unlimited online access. for two more free articles, or for unlimited online access.