Tag: tls
6 articles

Android 17 Bolsters Privacy with OS-Wide Encrypted Client Hello Support
Android 17 just got a major boost to online privacy with OS-wide Encrypted Client Hello support, making it harder for snoops to see which websites you're visiting. This new standard teams up with private DNS to keep your browsing habits private, shielding the domain names you visit from prying eyes.

Android 17 Bolsters Browsing Privacy with ECH Support
Android 17 just got a major boost to browsing privacy with the addition of Encrypted Client Hello (ECH) support, which teams up with private DNS to keep your online activities under wraps by hiding the domain names you visit. This means you can say goodbye to being profiled by advertisers and hello to a more private browsing experience.

OpenSSL Flaw Exposes Servers to Memory Exhaustion Attacks
A newly discovered OpenSSL flaw, dubbed HollowByte, leaves unpatched servers vulnerable to memory exhaustion attacks, where a mere 11 bytes can trigger the allocation of up to 131 KB of memory for a message that never arrives. This tiny trigger can bring a server to its knees, freezing memory and blocking critical connections.

OpenSSL Servers Vulnerable to Memory-Bloating DDoS Attacks
Beware: a simple 11-byte malicious input can cripple OpenSSL servers with a devastating DDoS attack, leaving them permanently bloated and vulnerable. This sneaky exploit, dubbed HollowByte, takes advantage of a weakness in OpenSSL's TLS handshake to drain server resources.

Weak RSA Keys Exposed in Widespread Use
Meet the badkeys project, an open-source service that scans public keys for vulnerabilities, which recently uncovered a surprising pattern of weak RSA keys in widespread use. By analyzing a massive dataset of real-world public keys, the team discovered a substantial number of keys with a suspicious structure, featuring regularly spaced blocks of zero bits and random data.

Exim BDAT Flaw Exposes GnuTLS Builds to Code Execution Risk
A newly discovered vulnerability, dubbed Dead.Letter, threatens Exim builds that use GnuTLS, allowing attackers to exploit a use-after-free flaw in BDAT handling and potentially execute malicious code. This critical flaw can be triggered when a specific sequence of BDAT and TLS commands is sent, leading to heap corruption and a heightened risk of code execution.