Forum Moderators: open

Message Too Old, No Replies

5pct of Web's Top 10,000 Sites Had Exploitable TLS Vulnerabilities

         

engine

12:46 pm on Mar 29, 2019 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



According to a new report from researchers at Ca' Foscari University of Venice in Italy and Tu Wien in Austria, 5% of the web's top 10,000 sites had exploitable TLS vulnerabilities. The top 10,000 HTTPS sites is based upon Alexa's stats.

These flaws were caused by a combination of issues in how sites implemented TLS encryption schemes and failures to patch known bugs, (of which there are many) in TLS and its predecessor, Secure Sockets Layer. But the worst thing about these flaws is they are subtle enough that the green padlock will still appear.


[wired.com...]

graeme_p

4:41 pm on Mar 30, 2019 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



But the worst thing about these flaws is they are subtle enough that the green padlock will still appear.


Maybe because the definition of security they are (implicitly) using is "the green padlock appears". TO be honest I usually think "job done" at that point/