Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / A few HTTPS inspection gear may weaken safety

A few HTTPS inspection gear may weaken safety

Latest Govt. Jobs 21:44:00 News Edit
HTTPS inspection weakens connection security.

Companies that use security products to inspect HTTPS traffic might inadvertently make their users' encrypted connections less secure and expose them to man-in-the-middle attacks, the U.S. Computer Emergency Readiness Team warns.
US-CERT, a division of the Department of Homeland Security, published an advisory after a recent survey showed that HTTPS inspection products don't mirror the security attributes of the original connections between clients and servers.
HTTPS inspection checks the encrypted traffic coming from an HTTPS site to make sure it doesn't contain threats or malware. It's performed by intercepting a client's connection to an HTTPS server, establishing the connection on the client's behalf and then re-encrypting the traffic sent to the client with a different, locally generated certificate. Products that do this essentially act as man-in-the-middle proxies.
In a typical enterprise environment, an HTTPS connection can even be intercepted and re-encrypted multiple times: at the network perimeter by gateway security products or data leak prevention systems and on endpoint systems by antivirus programs that need to inspect such traffic for malware.
The problem is that users' browsers no longer get to validate the real server certificates because that task falls to the interception proxy. And as it turns out, security products are pretty bad at validating server certificates.
Researchers from Google, Mozilla, Cloudflare, University of Michigan, University of Illinois Urbana-Champaign, University of California, Berkeley and the International Computer Science Institute recently conducted an investigation of HTTPS inspection practices.
They found that more than 10 percent of HTTPS traffic that originates from the U.S. and reaches Cloudflare's content delivery network is being intercepted. So are 6 percent of connections to e-commerce websites.
An analysis found that 32 percent of e-commerce and 54 percent of Cloudflare HTTPS connections that were intercepted became less secure than they would have been had users connected directly to the servers.
"Alarmingly, not only did intercepted connections use weaker cryptographic algorithms, but 10 to 40 percent advertised support for known-broken ciphers that would allow an active man-in-the-middle attacker to later intercept, downgrade, and decrypt the connection," the researchers said in their paper.
The reason is that browser makers have had a long time and the proper expertise to understand the potential quirks of TLS connections and certificate validation. There arguably are no better client-side implementations of TLS -- the encrypted protocol used for HTTPS -- than the ones in modern browsers.
Security product vendors use outdated TLS libraries, customize them and even attempt to re-implement some of the protocol's features, resulting in serious vulnerabilities.
Another widespread problem signaled by US-CERT in their advisory is that many HTTPS interception products don't properly validate the certificate chains presented by servers.
"Furthermore, certificate-chain verification errors are infrequently forwarded to the client, leading a client to believe that operations were performed as intended with the correct server," the organization said.
On the BadSSL website, organizations can check if their HTTPS inspection products improperly validate certificates or allow for insecure ciphers. The client test from Qualys SSL Labs also can check for some known TLS vulnerabilities and weaknesses.
The CERT Coordination Center at Carnegie Mellon University has published a blog post with more information on the common pitfalls of HTTPS interception, as well as a list of products that may be vulnerable.
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


Vivo V9 with dual rear cameras

Xiaomi Redmi 5 launch

Vodafone partners with Tecno to off...
A few HTTPS inspection gear may weaken safety A few HTTPS inspection gear may weaken safety Reviewed by Latest Govt. Jobs on 21:44:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Here new HP launches 'OMEN' gaming portfolio in India
    Entering the growing field of gaming with a bang, printing and personal computer major  HP ...
  • Fitbit Zip 2017 review
    Fitbit PROS: Clever, accurate tracking Expandable online service Integration with 3rd ...

Random Posts

  • Airtel New Your-Freedom VPN Working Trick of 2017
    Airtel New Your-Freedom VPN Working Trick of 2017
    25.02.2017 - 0 Comments
    YOUR FREEDOM IS A VPN WITH WHICH YOU CAN GET HIGH SPEED FREE INTERNET ON AIRTEL…UNLIKE NMD VPN, THIS IS…
  • Apple iPhone X production
    Apple iPhone X production
    30.01.2018 - 0 Comments
    Apple iPhone X production target halved for the first quarter to around 20 million units, Nikkei reported on…
  • Xiaomi Redmi 4A next sale on March 30: All you need to know
    Xiaomi Redmi 4A next sale on March 30: All you need to know
    23.03.2017 - 0 Comments
    Xiaomi Redmi 4A’s next sale on Amazon India and Mi.com will take place on March 30. Update: Xiaomi’s…
  • Facebook starts caution U.S. customers while they're sharing faux information
    Facebook starts caution U.S. customers while they're sharing faux information
    25.03.2017 - 0 Comments
    In a few months, you may no longer have to write “FAKE” below your friends’ Facebook posts. Fake news…
  • How to Move Windows 10 to SSD Without Reinstall Windows & Software
    How to Move Windows 10 to SSD Without Reinstall Windows & Software
    26.04.2016 - 0 Comments
    Hey Fellas, In This Tutorial, I am Going to Explain about How to Move / Transfer  Windows 10 to…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • Taotronics TT-BH22 Headphones Review
    We make it a ...
  • Bank wallets growing faster than e-wallets
    In the  bank ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on ...
  • You may now ship money and get paid returned in Gmail on Android
    In the ...
  • Fitbit Flex 2017 review
    Fitbit PROS ...

Random Posts

  • Quotes
    Quotes
    27.04.2016 - 0 Comments
    I admit, I really miss how things used to be. But I can also admit, that I've accepted the fact that things…
  • Top 9 nifty Gboard for Android hints you want to try
    Top 9 nifty Gboard for Android hints you want to try
    06.04.2017 - 0 Comments
    The only problem with Google's Gboard keyboard for Android is that I'm totally hooked on its best…
  • Best smartphones for selfie lovers: OnePlus 3T, Asus Zenfone selfie, Oppo F1S & others
    Best smartphones for selfie lovers: OnePlus 3T, Asus Zenfone selfie, Oppo F1S & others
    20.02.2017 - 0 Comments
    Selfies are here to stay and phone manufacturers are trying to cash-in on the craze. ET gives you a quick…
  • 14 Signs You’re Ruining Your First Date Unknowingly
    14 Signs You’re Ruining Your First Date Unknowingly
    27.04.2016 - 0 Comments
    Is your excitement and eagerness to impress your date ruining your first date? Here are 14 date ruining signs…
  • Reliance Jio speed is now as good as Airtel's, at least in Delhi
    Reliance Jio speed is now as good as Airtel's, at least in Delhi
    02.03.2017 - 0 Comments
    Jio 4G service is still a work in progress. Although it was launched in September first…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!