Online banking encryption broken
But attack is difficult, so don't panic, security expert says
CBC News
Posted: Sep 20, 2011 10:23 AM ET
Last Updated: Sep 20, 2011 7:59 PM ET
Related
Related Links
External Links
(Note:CBC does not endorse and is not responsible for the content of external links.)
Researchers have provided details of their attack to browser makers and Opera has already implemented a fix. (CBC)Security researchers have developed a potential cyber attack that could decrypt secure communications used by online banking and payment sites.
"The attack breaks the confidentiality model of the protocol … potentially affecting the security of transactions on millions of sites," wrote Dennis Fisher on ThreatPost, an internet security news blog run by the antivirus maker Kaspersky Lab.
The attack targets TLS (transport layer security) 1.0, the encryption mechanism used by websites accessed using https (secure hypertext transfer protocol).
Juliano Rizzo of Buenos Aires is set to demonstrate a browser-based version of the attack, called BEAST (Browser Exploit Against SSL/TLS) Friday at the Ekoparty security conference in his hometown.
The attack, developed by Rizzo and his Vietnamese colleague, Thai Duong, is the first to exploit a flaw in the security protocol known as TLS 1.0 that has been known for a long time, but was previously thought to be unexploitable.
The researchers have already provided details of their attack to browser makers.
According to ThreatPost, the Opera browser has already implemented a fix to thwart the attack.
The researchers told ThreatPost that similar attacks could be used not just against web browsers, but services such as instant messaging or virtual private network (VPN) clients that use SSL, the predecessor to TLS.
In some cases, known fixes to the vulnerability are not compatible with the applications, suggesting that the only solution is to switch to a new encryption protocol.
Newer versions of TLS without the vulnerability have been available since 2006, but most existing connections rely on the vulnerable version 1.0 because only that version is supported by the tools used by most websites to deploy TLS.
Recommendations for consumers
In the meantime, "don't panic," suggested Chester Wisniewski, a senior security adviser at the internet security firm Sophos Canada. "We will not know all the details until they are presented on Friday, but preliminary information ... suggests this will be a difficult attack."
He noted that according to ThreatPost, the attacker must be able to intercept the user's communications.
"For most users this is only possible on an open WiFi connection like you get at the café or airport," he told CBC News in an email. "You should never use open WiFi to conduct secure transactions like banking, whether there are known weaknesses in TLS or not."
The attacker must also be able to load code into the user's browser — something that anti-virus software should protect against, Wisniewski added.
Adam Wosotowsky, principal engineer for internet security firm McAfee, said he believes that for the average consumer, the risk of online banking or e-commerce "is still only as high as the risk really was before."
That's because other, less sophisticated attacks already exist to get people's banking information, he said. If someone is capable of infecting your computer with malicious code, it would be far easier for them to simply log everything you type into your keyboard to get your username and password, than to decrypt your bank sessions, he suggested.
Wosotowsky recommended that people concerned about the security of online banking should buy a cheap laptop to use only for that purpose — that minimizes the chance of getting the comptuer infected with any kind of malware.
On the other hand, he said the new attack is "definitely something that is worrying" and may be used in other kinds of attacks, such as to help to get into a secure network.
"Hopefully this pushes people to using the higher versions of TLS and higher versions of SSL," he said.
Share Tools
Top News Headlines
- Canadian Pacific strikers face back-to-work legislation
- Labour Minister Lisa Raitt is prepared to end the Canadian Pacific Railway strike if necessary, after both CP and the union rejected a proposal for voluntary arbitration by the government-appointed negotiator on Sunday. Raitt says she is "extremely disappointed."
more »
- Quebec students and province to resume talks
- Quebec's university student federation has confirmed negotiations between student leaders and the provincial government will resume Monday afternoon. more »
- Syrian regime denies role in Houla massacre
- The UN Security Council condemned the Syrian regime at an emergency meeting Sunday, holding president Bashar al-Assad's military responsible for the massacre of more than 100 people, dozens of whom were children younger than 10 years old. more »
- Ryder Hesjedal wins prestigious Giro d'Italia
- Victoria native Ryder Hesjedal has become the first Canadian to win one of the cycling world's three Grand Tour events, wrapping up the 2012 Giro d'Italia with an excellent performance in the final stage in Milan. more »
- Neighbour may have helped find missing kids in Mexico
- Two Winnipeg children who had been missing for nearly four years were found in Mexico after a man raised concerns about his neighbour, according to a private investigator. more »
Latest World News Headlines
- Egypt presidential candidates allege vote fraud
- Three top candidates in Egypt's presidential race have filed appeals to the election commission, alleging violations in the first round vote that they say could change the outcome. more »
- Ryder Hesjedal wins prestigious Giro d'Italia
- Victoria native Ryder Hesjedal has become the first Canadian to win one of the cycling world's three Grand Tour events, wrapping up the 2012 Giro d'Italia with an excellent performance in the final stage in Milan. more »
- IMF chief blasted for chastising Greeks on tax evasion
- International Monetary Fund chief Christine Lagarde is backtracking from recent remarks that she has more sympathy for poor African children than Greeks suffering under the country's economic problems and austerity measures. more »
- Nepal PM calls new elections after constitution failure
- Nepal's prime minister called new elections for November after the term of the Constituent Assembly expired at midnight Sunday without political leaders completing the task of writing a new constitution. more »
Dispatches »
- Foreign slaves serving the U.S. military machine May. 24, 2012 3:33 PM How does a hairdresser recruited for work in Dubai, wind up slaving for the U.S. military in a war zone in Iraq? There are tens of thousands serving in what's come to be known as America's "Invisible Army."
Connect Newsroom Blog
Etan Patz, Brian Banks & 50 Shades of Grey May. 25, 2012 8:56 PM On his first full day of his new life, former football star Brian Banks joins us live.
- Seniors float above Montreal's Quartier Latin
- Accused in blast that killed Alberta mom handled her funds
- Remains found in bag on Cape Breton river ID'd
- Neighbour may have helped find missing kids in Mexico
- Quebec students and province to resume talks
- Lip-dub marriage proposal an internet hit
- Syrian regime denies role in Houla massacre
- B.C. NDP calls for unity in fighting coast guard closure
- Canadian Pacific strikers face back-to-work legislation

