[WEB SECURITY] Turning off SSL after a hack?

Jeremiah Grossman jeremiah at whitehatsec.com
Wed Jul 12 12:46:27 EDT 2006

After reading RSnake's recent blog post, SSL Can Hurt Security [1],  
an article [2] appeared on CNN where some of the subject matter  
crossed paths. The US State Department suffered a "large scale  
computer break-in". Here's the interesting bits come in:

"After the State Department break-ins, many employees were instructed  
to change their passwords. The department also temporarily disabled a  
technology known as secure sockets layer, used to transmit encrypted  
information over the Internet.

Hackers can exploit weaknesses in this technology to break into  
computers, and they can use the same technology to transmit stolen  
information covertly off a victim's network."

I have a hard time swallowing that SSL was actually turned off. More  
likely the author didn't get the facts straight. But who knows,  
stranger things have happened.

[1] SSL Can Hurt Security

[2] Hackers target State Dept. computers


Jeremiah Grossman
Founder and CTO
WhiteHat Security, Inc.

