A pair of researchers recently created a tool called Browser Exploit Against SSL/TLS, or BEAST, which enables an...
By submitting your email address, you agree to receive emails regarding relevant topic offers from TechTarget and its partners. You can withdraw your consent at any time. Contact TechTarget at 275 Grove Street, Newton, MA.
attacker to intercept and decrypt SSL cookies on the same network by performing a "blockwise-adaptive chosen-plaintext" attack on encrypted packets. Does this BEAST SSL tool give attackers a powerful new weapon to break SSL/TLS encryption; how much of a risk does it pose to enterprises, and are there any mitigation tactics that can be put in place?
Ask the Expert!
Have questions about enterprise information security threats for expert Nick Lewis? Send them via email today! (All questions are anonymous.)
Before we assess the threat posed by the BEAST SSL tool, let's examine the context. Researchers Juliano Rizzo and Thai Duong expanded on Bruce Schneier and David Wagner’s analysis (.pdf) from 1999. In looking at SSL 3.0, Schneier and Wagner found that, despite several "minor" flaws, including the one mentioned above, SSL was still largely secure enough for broad use.
Dig Deeper on SSL and TLS VPN Security
Related Q&A from Nick Lewis
Malware authors are adopting software wrapping to hide malicious code and avoid detection. Expert Nick Lewis explains how to defend against the ...continue reading
Malicious software using legitimate digital certificates is reportedly on the rise. Expert Nick Lewis explains how to mitigate the risks of digitally...continue reading
Malware authors are using power consumption tracking-malware to eavesdrop on and attack mobile devices. Expert Nick Lewis explains the threat and how...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.