Reading Tools
Related Stories
Hackers disrupt Australian government Web s...
2010-2-10 15:48:23
Police seize master-hacker suspects
2010-2-8 18:40:41
Hacker's bid to stop being tried in US fail...
2009-10-10
Police arrest two over hacker attack
2009-9-15 15:47:54
Biggest hack attack gang caught
2009-8-21 15:06:31
RESEARCHERS have uncovered new ways that criminals can spy on Internet users even if they're using secure connections to banks, online retailers or other sensitive websites.
The attacks demonstrated at the Black Hat conference in Las Vegas show how determined hackers can sniff around the edges of encrypted Internet traffic to pick up clues about what their targets are up to.
It's like tapping a telephone conversation and hearing muffled voices that hint at the tone of the conversation.
The problem lies in the way web browsers handle Secure Sockets Layer, or SSL, encryption technology, according to Robert Hansen and Josh Sokol, who spoke to a packed room of security experts.
Encryption forms a kind of tunnel between a browser and a website's servers. It scrambles data so it's indecipherable to prying eyes.
SSL is widely used on sites trafficking in sensitive information, such as credit card numbers, and its presence is shown as a padlock in the browser's address bar.
SSL is a widely attacked technology, according to Hansen and Sokol, with attacks yielding all sorts of information.