Attacking the edges of secure Internet traffic
July 30, 2010 By JORDAN ROBERTSON , AP Technology Writer
A man passes a logo of the Black Hat technology conference in Las Vegas on Wednesday, July 28, 2010. (AP Photo/Isaac Brekken)
(AP) -- Researchers have uncovered new ways that criminals can spy on Internet users even if they're using secure connections to banks, online retailers or other sensitive Web sites.
The attacks demonstrated at the Black Hat conference here show how determined hackers can sniff around the edges of encrypted Internet traffic to pick up clues about what their targets are up to.
It's like tapping a telephone conversation and hearing muffled voices that hint at the tone of the conversation.
The problem lies in the way Web browsers handle Secure Sockets Layer, or SSL, encryption technology, according to Robert Hansen and Josh Sokol, who spoke to a packed room of several hundred security experts.
Encryption forms a kind of tunnel between a browser and a website's servers. It scrambles data so it's indecipherable to prying eyes.
SSL is widely used on sites trafficking in sensitive information, such as credit card numbers, and its presence is shown as a padlock in the browser's address bar.
SSL is a widely attacked technology, but the approach by Hansen and Sokol wasn't to break it. They wanted to see instead what they could learn from what are essentially the breadcrumbs from people's secure Internet surfing that browsers leave behind and that skilled hackers can follow.
Their attacks would yield all sorts of information. It could be relatively minor, such as browser settings or the number of Web pages visited. It could be quite substantial, including whether someone is vulnerable to having the "cookies" that store usernames and passwords misappropriated by hackers to log into secure sites.
Hansen said all major browsers are affected by at least some of the issues.
"This points to a larger problem - we need to reconsider how we do electronic commerce," he said in an interview before the conference, an annual gathering devoted to exposing the latest computer-security vulnerabilities.
For the average Internet user, the research reinforces the importance of being careful on public Wi-Fi networks, where an attacker could plant himself in a position to look at your traffic. For the attacks to work, the attacker must first have access to the victim's network.
Hansen and Sokol outlined two dozen problems they found. They acknowledged attacks using those weaknesses would be hard to pull off.
The vulnerabilities arise out of the fact people can surf the Internet with multiple tabs open in their browsers at the same time, and that unsecured traffic in one tab can affect secure traffic in another tab, said Hansen, chief executive of consulting firm SecTheory. Sokol is a security manager at National Instruments Corp.
Their talk isn't the first time researchers have looked at ways to scour secure Internet traffic for clues about what's happening behind the curtain of encryption. It does expand on existing research in key ways, though.
"Nobody's getting hacked with this tomorrow, but it's innovative research," said Jon Miller, an SSL expert who wasn't involved in the research.
Miller, director of Accuvant Labs, praised Hansen and Sokol for taking a different approach to attacking SSL.
"Everybody's knocking on the front door, and this is, 'let's take a look at the windows,'" he said. "I never would have thought about doing something like this in a million years. I would have thought it would be a waste of time. It's neat because it's a little different."
Another popular talk at Black Hat concerned a new attack affecting potentially millions of home routers. The attack could be used to launch the kinds of attacks described by Hansen and Sokol.
Researcher Craig Heffner examined 30 different types of home routers from companies including Actiontec Electronics Inc. and Cisco Systems Inc.'s Linksys and found that more than half of them were vulnerable to his attack.
He tricked Web browsers that use those routers into letting him access administrative menus that only the routers' owners should be able to see. Heffner said the vulnerability is in the browsers and illustrates a larger security problem involving how browsers determine that the sites they visit are trustworthy.
The caveat is he has to first trick someone into visiting a malicious site, and it helps if the victim hasn't changed the router's default password.
Still: "Once you're on the router, you're invisible - you can do all kinds of things," such as controlling where the victim goes on the Internet, Heffner said.
©2010 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.
-
Hackers expose weakness in visiting trusted sites
Aug 02, 2009 |
not rated yet |
0
-
VeriSign to spend more than $300M on tech upgrades (Update)
Mar 11, 2010 |
not rated yet |
0
-
Patch for flaw in key Internet protocol
Jan 15, 2010 |
not rated yet |
0
-
Cyber criminals cloak their tracks
Feb 13, 2008 |
not rated yet |
0
-
Web browsers and iPhone hacked at contest
Mar 26, 2010 |
not rated yet |
0
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (30) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (3) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (1) |
0
-
Force free body diagram problem on gym equipment
1 hour ago
-
Empirical data regarding shower heads and water
9 hours ago
-
feed hold button on CNC lathe
Feb 09, 2012
-
RFAC in Fortran
Feb 09, 2012
-
dynamics 2/32
Feb 08, 2012
-
dynamics
Feb 08, 2012
- More from Physics Forums - General Engineering
More news stories
Netflix light on flicks as viewers soak up TV shows
Like most fresh faces that arrive in Hollywood, Netflix wanted to be a movie star. But now it's learning what many in Tinseltown have known for decades: Movies are sexy, but the real money is in television.
6 minutes ago |
not rated yet |
0
Sony's Hirai refuses to abandon dire TV business
Struggling Japanese entertainment giant Sony will not abandon its cash-bleeding television business, its incoming CEO says, but he acknowledges tough decisions lie ahead including over redundancies.
36 minutes ago |
not rated yet |
0
New error-correcting codes guarantee the fastest possible rate of data transmission
Error-correcting codes are one of the triumphs of the digital age. Theyre a way of encoding information so that it can be transmitted across a communication channel such as an optical fiber o ...
Technology / Computer Sciences
3 hours ago |
5 / 5 (3) |
2
|
Small modular reactor design could be a 'SUPERSTAR'
(PhysOrg.com) -- Though most of today's nuclear reactors are cooled by water, we've long known that there are alternatives; in fact, the world's first nuclear-powered electricity in 1951 came from a reactor ...
Technology / Energy & Green Tech
2 hours ago |
5 / 5 (4) |
9
|
Advanced power-grid model finds low-cost, low-carbon future in West
(PhysOrg.com) -- The least expensive way for the Western U.S. to reduce greenhouse gas emissions enough to help prevent the worst consequences of global warming is to replace coal with renewable and other ...
Technology / Energy & Green Tech
2 hours ago |
5 / 5 (1) |
3
|
Experts reveal how plants don't get sunburn
(PhysOrg.com) -- Experts at the University of Glasgow have discovered how plants survive the harmful rays of the sun.
Fool's gold may prove an unlikely alternative to overexploited catalytic materials
Catalytic materials, which lower the energy barriers for chemical reactions, are used in everything from the commercial production of chemicals to catalytic converters in car engines. However, with current catalytic materials ...
Curry spice component may help slow prostate tumor growth
Curcumin, an active component of the Indian curry spice turmeric, may help slow down tumor growth in castration-resistant prostate cancer patients on androgen deprivation therapy (ADT), a study from researchers ...
Unpicking HIV’s invisibility cloak
Drug researchers hunting for alternative ways to treat human immunodeficiency virus (HIV) infections may soon have a novel targetits camouflage coat. HIV hides inside a cloak unusually rich in a sugar ...
What lies beneath: Mapping hidden nanostructures
The ability to diagnose and predict the properties of materials is vital, particularly in the expanding field of nanotechnology. Electron and atom-probe microscopy can categorize atoms in thin sheets of material, ...
To avoid early labor and delivery, weight and diet changes not the answer
One of the strongest known risk factors for spontaneous or unexpected preterm birth any birth that occurs before the 37th week of pregnancy, most often without a known cause is already having had one. For women ...