Et encore un peu d'eau à ajouter à notre moulin. Récemment, une faille de sécurité assez énorme dénommée
DROWN a été rendue publique.
Pour les plus technophiles, la faille exploite le fait que certains serveurs supportent une technologie depuis longtemps dépréciée : SSLv2.
Il faut savoir que cette faille rend vulnérable plus d'un tiers des serveurs HTTP
S au monde, et dans certaines conditions, même ceux qui n'implémentent plus cette vieille technologie au profit de TLS (pour plus de détails, MP).
La faille est relativement "facilement" exploitable, et à moindre coût. Des sites/services comme
yahoo,
ovh,
orange sont notamment touchés. Je vous laisse imaginer le bordel.
Quel est le rapport avec le ski vous allez me dire. Le voici :
drownattack.com a écrit :What factors contributed to DROWN?
For the third time in a year, a major Internet security vulnerability has resulted from the way cryptography was weakened by U.S. government policies that restricted exporting strong cryptography until the late 1990s. Although these restrictions, evidently designed to make it easier for NSA to decrypt the communication of people abroad, were relaxed nearly 20 years ago, the weakened cryptography remains in the protocol specifications and continues to be supported by many servers today, adding complexity—and the potential for catastrophic failure—to some of the Internet’s most important security features.
The U.S. government deliberately weakened three kinds of cryptographic primitives: RSA encryption, Diffie-Hellman key exchange, and symmetric ciphers. FREAK exploited export-grade RSA, and Logjam exploited export-grade Diffie-Hellman. Now, DROWN exploits export-grade symmetric ciphers, demonstrating that all three kinds of deliberately weakened crypto have come to put the security of the Internet at risk decades later.
Today, some policy makers are calling for new restrictions on the design of cryptography in order to prevent law enforcement from “going dark.” While we believe that advocates of such backdoors are acting out of a good faith desire to protect their countries, history’s technical lesson is clear: weakening cryptography carries enormous risk to all of our security.