Category

Encryption

DROWN Attack (CVE-2016-0800), Turing Award and Leo’s Oscar

Hello, A new security vulnerability (“DROWN“: Decrypting RSA with Obsolete and Weakened eNcryption) affecting OpenSSL was disclosed yesterday which allows an attacker to decrypt secure TLS sessions and steal sensitive data such as passwords and credit cards information. All applications that rely on TLS protocol (like websites and email) are therefore affected. The vulnerability (id:...
Read More

Logjam Security Vulnerability (CVE-2015-4000)

Following the continuous revealing of security vulnerabilities with the most unimaginable names such as “Shellshock” (CVE-2014-6271 and CVE-2014-7169), “POODLE” (CVE-2014-3566), “POODLE 2.0” (CVE-2014-8730) and “GHOST” (CVE-2015-0235) affecting SSL, TLS and other widely-used security protocols, it was just a matter of time until the curtain rolled revealing the latest security vulnerability this time affecting Diffie-Hellman algorithm for...
Read More