Online banking, credit card data: Facebook security protocol for internet banking has serious weaknesses says warning
Related
Top Stories
- UPA-2 anniversary today, to showcase achievements of UPA-1
- 1993 Mumbai blasts: Sanjay Dutt shifted to Pune's Yerwada Jail
- Sreesanth spent Rs 1.95L on clothes, bought friend BlackBerry, paid in cash: Police
- BCCI cashes Pune guarantee, Sahara walks out of IPL
- BSE Sensex opens in green, up 91 points in early trade

The protocol that provides security for online banking, credit card data and social networking site Facebook has "major weaknesses" which may lead to interception of sensitive personal data, UK scientists warn.
The Transport Layer Security (TLS) protocol is used by millions of people on a daily basis. It provides security for online banking, as well as for credit card data when shopping on the Internet.
In addition, many email systems in the workplace use it, as well as a number of big companies including Facebook and Google.
Professor Kenny Paterson from the Information Security Group at Royal Holloway University and researcher Nadhem AlFardan found that a so-called 'Man-in-the Middle' attack can be launched against TLS and sensitive personal data can be intercepted in this way.
They have identified a flaw in the way in which the protocol terminates TLS sessions. This leaks a small amount of information to the attacker, who can use it to gradually build up a complete picture of the data being sent.
"While these attacks do not pose a significant threat to ordinary users in its current form, attacks only get better with time. Given TLS's extremely widespread use, it is crucial to tackle this issue now," Paterson said in a statement.
"Luckily we have discovered a number of countermeasures that can be used. We have been working with a number of companies and organisations, including Google, Oracle and OpenSSL, to test their systems against attack and put the appropriate defences in place," Paterson added.
Editors’ Pick
- Fixing probe now reaches Bollywood, son of Dara Singh held
- BCCI cashes Pune guarantee, Sahara walks out of IPL
- Sreesanth spent Rs 1.95L on clothes, bought friend BlackBerry, paid in cash: Police
- Delhi firm with MoD as client is linked to Pak cyberattacks
- After Infosys, iGATE sacks Phaneesh Murthy for sexual misconduct
- 2 weeks after harassment, Haryana schoolgirls return, cops in tow
- UPA-2 anniversary today, to showcase achievements of UPA-1


RBI gears up for plastic notes as 20% paper bills get soiled
Home prices near most affordable levels in over 30 yrs: HDFC
Nokia sees growth in sales of Lumia smartphones in India
Indian rupee may stabilise back to 54 mark in short-term: Experts




















