Secure Sockets Layer/Transport Layer Security is the foundational technology that secures Web transactions and communications, but it is not infallible. . New research dubbed Lucky13 reveals that SSL/TLS is at risk from a theoretical timing attack that could expose encrypted data. TLS headers include 13 bytes of data used for the secure handshake protocol, said researchers from Royal Holloway at the University of London, and they can be exploited in the Lucky13 attack. The link for this article located at eSecurityPlanet is no longer available. . Studies indicate SSL/TLS is susceptible to the Lucky13 timing vulnerability, threatening the confidentiality of encrypted information.. SSL Security, Timing Attack, Secure Communications, Web Encryption. . Dave Wreski
Get the latest Linux and open source security news straight to your inbox.