Security protocol for net banking, FB has serious weaknesses

The protocol that provides security for online banking, credit card data and social networking site Facebook has "major weaknesses" which may lead to interception of sensitive personal data, UK scientists warn.

By:PTI
| Updated on: Feb 04 2013, 13:38 IST

The protocol that provides security for online banking, credit card data and social networking site Facebook has 'major weaknesses' which may lead to interception of sensitive personal data, UK scientists warn.

The Transport Layer Security (TLS) protocol is used by millions of people on a daily basis. It provides security for online banking, as well as for credit card data when shopping on the Internet.

You may be interested in

MobilesTablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
23% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage

In addition, many email systems in the workplace use it, as well as a number of big companies including Facebook and Google.

Also read
Looking for a smartphone? To check mobile finder click here.

Professor Kenny Paterson from the Information Security Group at Royal Holloway University and researcher Nadhem AlFardan found that a so-called 'Man-in-the Middle' attack can be launched against TLS and sensitive personal data can be intercepted in this way.

They have identified a flaw in the way in which the protocol terminates TLS sessions. This leaks a small amount of information to the attacker, who can use it to gradually build up a complete picture of the data being sent.

'While these attacks do not pose a significant threat to ordinary users in its current form, attacks only get better with time. Given TLS's extremely widespread use, it is crucial to tackle this issue now,' Paterson said in a statement.

'Luckily we have discovered a number of countermeasures that can be used. We have been working with a number of companies and organisations, including Google, Oracle and OpenSSL, to test their systems against attack and put the appropriate defences in place,' Paterson added.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on Whatsapp channel,Twitter, Facebook, Google News, and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 04 Feb, 13:33 IST
NEXT ARTICLE BEGINS