Online banking encryption broken
But attack is difficult, so don't panic, security expert says
CBC News
Posted: Sep 20, 2011 10:23 AM ET
Last Updated: Sep 20, 2011 7:59 PM ET
Related
Related Links
External Links
(Note:CBC does not endorse and is not responsible for the content of external links.)
Researchers have provided details of their attack to browser makers and Opera has already implemented a fix. (CBC)Security researchers have developed a potential cyber attack that could decrypt secure communications used by online banking and payment sites.
"The attack breaks the confidentiality model of the protocol … potentially affecting the security of transactions on millions of sites," wrote Dennis Fisher on ThreatPost, an internet security news blog run by the antivirus maker Kaspersky Lab.
The attack targets TLS (transport layer security) 1.0, the encryption mechanism used by websites accessed using https (secure hypertext transfer protocol).
Juliano Rizzo of Buenos Aires is set to demonstrate a browser-based version of the attack, called BEAST (Browser Exploit Against SSL/TLS) Friday at the Ekoparty security conference in his hometown.
The attack, developed by Rizzo and his Vietnamese colleague, Thai Duong, is the first to exploit a flaw in the security protocol known as TLS 1.0 that has been known for a long time, but was previously thought to be unexploitable.
The researchers have already provided details of their attack to browser makers.
According to ThreatPost, the Opera browser has already implemented a fix to thwart the attack.
The researchers told ThreatPost that similar attacks could be used not just against web browsers, but services such as instant messaging or virtual private network (VPN) clients that use SSL, the predecessor to TLS.
In some cases, known fixes to the vulnerability are not compatible with the applications, suggesting that the only solution is to switch to a new encryption protocol.
Newer versions of TLS without the vulnerability have been available since 2006, but most existing connections rely on the vulnerable version 1.0 because only that version is supported by the tools used by most websites to deploy TLS.
Recommendations for consumers
In the meantime, "don't panic," suggested Chester Wisniewski, a senior security adviser at the internet security firm Sophos Canada. "We will not know all the details until they are presented on Friday, but preliminary information ... suggests this will be a difficult attack."
He noted that according to ThreatPost, the attacker must be able to intercept the user's communications.
"For most users this is only possible on an open WiFi connection like you get at the café or airport," he told CBC News in an email. "You should never use open WiFi to conduct secure transactions like banking, whether there are known weaknesses in TLS or not."
The attacker must also be able to load code into the user's browser — something that anti-virus software should protect against, Wisniewski added.
Adam Wosotowsky, principal engineer for internet security firm McAfee, said he believes that for the average consumer, the risk of online banking or e-commerce "is still only as high as the risk really was before."
That's because other, less sophisticated attacks already exist to get people's banking information, he said. If someone is capable of infecting your computer with malicious code, it would be far easier for them to simply log everything you type into your keyboard to get your username and password, than to decrypt your bank sessions, he suggested.
Wosotowsky recommended that people concerned about the security of online banking should buy a cheap laptop to use only for that purpose — that minimizes the chance of getting the comptuer infected with any kind of malware.
On the other hand, he said the new attack is "definitely something that is worrying" and may be used in other kinds of attacks, such as to help to get into a secure network.
"Hopefully this pushes people to using the higher versions of TLS and higher versions of SSL," he said.
Share Tools
Top News Headlines
- Canadian Pacific strikers face back-to-work legislation
- Labour Minister Lisa Raitt is prepared to end the Canadian Pacific Railway strike if necessary, after both CP and the union rejected a proposal for voluntary arbitration by the government-appointed negotiator on Sunday. Raitt says she is "extremely disappointed." more »
- Syrian regime denies role in Houla massacre
- The UN Security Council condemned the Syrian regime at an emergency meeting Sunday, holding president Bashar al-Assad's military responsible for the massacre of more than 100 people, dozens of whom were children younger than 10 years old. more »
- Ryder Hesjedal wins prestigious Giro d'Italia
- Victoria native Ryder Hesjedal has become the first Canadian to win one of the cycling world's three Grand Tour events, wrapping up the 2012 Giro d'Italia with an excellent performance in the final stage in Milan. more »
- Neighbour may have helped find missing kids in Mexico
- Two Winnipeg children who had been missing for nearly four years were found in Mexico after a man raised concerns about his neighbour, according to a private investigator. more »
Latest Technology & Science News Headlines
- South Africa, Australia to share world's largest telescope
- South Africa and Australia will jointly host the Square Kilometre Array, which promises to be the world's largest telescope, the international consortium in charge of the project said Friday. more »
- Bonavista, N.L., 'coyote' was really wolf, tests confirm
- Wolves have not been seen in Newfoundland since around 1930 and were believed to have been hunted to extinction on the island, but genetic tests have confirmed that an 82-pound animal shot on the Bonavista Peninsula in March was, in fact, a wolf. more »
- Once-rare argus butterfly thriving thanks to climate change
- Global warming is threatening the existence of many species, such as the giant polar bear, but in the case of Britain's brown argus butterfly, it took a species in trouble and made it thrive. more »
- Yahoo scraps digital magazine designed for iPad
- Yahoo has killed Livestand, a tablet magazine, just six months after its debut on the iPad. more »
Bob McDonald's Blog
Government to shut down unique fresh water research area May. 25, 2012 12:31 PM The Experimental Lakes Area research facility in Northern Ontario is being closed down after 44 years of providing invaluable data to scientists in Canada and internationally, a decision that has stunned researchers and environmental groups.
Quirks & Quarks
- May 26: Before the Lights Go Out May. 25, 2012 4:15 PM A new book, "Before the Lights Go Out: Conquering the Energy Crisis Before It Conquers Us", suggests that the unpredictable, unplanned, ad-hoc way our energy use developed in the past will shape our energy future.
Latest Features
- Seniors float above Montreal's Quartier Latin
- Accused in blast that killed Alberta mom handled her funds
- Remains found in bag on Cape Breton river ID'd
- Neighbour may have helped find missing kids in Mexico
- Quebec students and province to resume talks
- Lip-dub marriage proposal an internet hit
- Syrian regime denies role in Houla massacre
- B.C. NDP calls for unity in fighting coast guard closure
- Canadian Pacific strikers face back-to-work legislation

