Snappy newsletters. Simple Facebook sharing. Spirited comments. Sweet features are waiting… GET THEM NOW!

Patch for Major Security Flaw Is Ineffective

Widely distributed fix for Internet failing only slows the damage

By Harry Kimball,  Newser Staff

Posted Aug 9, 2008 11:57 AM CDT

(Newser) – A fatal flaw in Internet security has a patch, but it’s a leaky one, the New York Times reports. Yesterday, a Russian scientist demonstrated an attack that secretly redirected web traffic. It took him just hours using standard equipment; before the patch, it would have taken seconds. Thieves could use the method to hijack a user’s bank or credit card information.

And it’s not just academic. “We have already been seeing attacks in the wild for the past two weeks,” a clued-in consultant said. Veteran Internet technologists were not surprised. “What makes this so frustrating is that no one has been listening to what we have been saying for the past 17 years,” one professor said. There are at least two domain name systems that are more secure.

Dan Kaminsky, director of penetration testing for Seattle-based computer security consultant IOActive.
Dan Kaminsky, director of penetration testing for Seattle-based computer security consultant IOActive.   (AP Photo)
An online lending site perhaps vulnerable to Internet crime.
An online lending site perhaps vulnerable to Internet crime.   (AP Photo)
The security patch has been distributed to most of the affected servers worldwide.
The security patch has been distributed to most of the affected servers worldwide.   (AP Photo)
« Prev« Prev | Next »Next » Slideshow

They are relying on infrastructure that was not intended to do what people assume it does."
- Clifford Neuman, USC

« Prev« Prev | Next »Next » Slideshow
To report an error on this story, notify our editors.
A snapshot of the day's best news stories.
 
COMMENTS
Be the first to comment on this story.

More Newser Stories

'Every Network Is at Risk' Thanks to Bug

Hacked Home Security Cams Link to Bedroom Scenes

Hackers Hit Internet Giant VeriSign

Coming This Week: Dot-Anything

The Year's Priciest Domain Names


NEWS FROM OUR PARTNERS
Other Sites We Like:   24/7 Wall St.   |   Betty Confidential   |   BuzzFeed   |   Cracked   |   Fark   |   Timelines   |   The Frisky   |   Geek Sugar   |   NewsOne