Critical Flaw in Internet Commerce Security Standards Discovered, Already Fixed

Software makers have identified a serious vulnerability in the security standards used by most online commerce sites, but assures consumers that the issue has been resolved. The discovery was made by a team at Lucent Technologies' Bell Labs, with RSA Data Security Inc. providing the fix. The flaw, if exploited, could have allowed hackers to access sensitive online transactions, but would have required a significant amount of time and effort, making an actual breach unlikely.

Key Takeaways:

  • A critical flaw was discovered in the security standards used by most online commerce sites on the Internet.
  • The flaw, if exploited, could have allowed hackers to access sensitive online transactions.
  • A hacker would have had to send approximately 1 million messages to the targeted server to break in, a process that would be time-consuming and easily detectable.
  • The complexity of the flaw made it implausible that a break-in could be completed in a reasonable amount of time.
  • RSA Data Security Inc. has developed new software code that "fundamentally eliminates this whole class of attack".
  • The fix will be released next month, with RSA Data Security advising that the industry's effectiveness in responding to such threats is crucial in minimizing or eliminating the threat.
  • Software companies take the issue seriously, acknowledging that new discoveries of flaws in the system will always be made, and the industry must respond effectively to mitigate the risk.

Statistics:

  • Approximately 1 million messages would have had to be sent to the targeted server to break in.
  • The fix for the flaw will be released next month.
  • According to RSA Data Security, the industry's response to minimizing or eliminating such threats is crucial.

Sources:

  • Reuters, PALO ALTO, Calif. -- Software makers said Friday they discovered a serious flaw in the security standards underlying most electronic commerce sites on the Internet, but that consumers need not worry.... (Reuters)
  • Quote from Scott Schnell, vice president at RSA Data Security Inc., "It is a serious flaw, and if it had been discovered by a bad guy, it could have been used surreptitiously to get into consumers' online banking transactions and other things."
  • Quote from Daniel Bleichenbacher, the computer scientist at Lucent Technologies Inc.'s Bell Labs, "It's kind of hard to imagine that someone would break into a server that way."