When you talk on the Internet, you need to agree on a language with which to communicate. What if you want to talk privately? Well, there’s encryption for that. But just like any other sort of communication, you also need to have a form of encryption that you can use mutually with whomever you’re talking to. Since not all browsers use the same algorithms, servers sometimes have to retain compatibility with algorithms that can be quite dangerous. Google has just recently discovered an exploit that at this moment can affect millions of browsers worldwide that use such an algorithm, and we’re going to talk about it!

What Happened?

Remember that Heartbleed bug that was being reported in almost every tech website? Here’s the run-down if you don’t want to read an entire wall of text: OpenSSL (the encryption algorithm library used by many websites around the world) had a hole in it. Most medium and large websites plugged it up successfully by simply upgrading OpenSSL. That was all done and dusted until something else happened.

This time, what is being known as the POODLE exploit is once again plaguing Secure Sockets Layer (SSL), albeit a different version of it entirely. SSL 3.0 has a serious bug that allows hackers to easily decrypt cookies sent over the HTTP protocol. This will let them see personal information belonging to your login session and even allow them to impersonate you.

The Solution

SSL 3.0 is very old cryptography, dating back to the times when MySpace was still gaining traction as a social media website. In fact, the term “social media” wasn’t even very popular back then. Many of today’s millenials were either entering their teenage years or still playing in the dirt at recess in fifth grade. That’s how old it is, and servers are still using it!

poodlebug-ssllock

Since then some major improvements have been made, such as Transport Layer Security (TLS). This new cryptographic protocol eliminates many of the big issues that were present in SSL, such as vulnerabilities that led to certain attacks (such as cipher block chaining which was resolved in TLS 1.1). The only reason TLS needed a new acronym was that it was no longer “interoperable” in SSL. What we industrial know-it-alls mean when we say that something is “interoperable” is that it’s able to work with older versions of something.

So, SSL 3.0 is dead and now we’re using something known as TLS 1.2. The only problem is that there are still many browsers using SSL 3.0 for data transmission. Servers still support it as a safe fallback in case the browsers connecting to them do not support TLS. The worst part is that even if your browser advertises its compatibility with TLS, there’s no guarantee that the server won’t respond with SSL 3.0. Hackers can use this to force your browser and the servers sending you data to stick to the old protocol. For this reason and this reason only, the POODLE exploit is still a big deal.

Google has a proposal: Why don’t we just stop supporting SSL 3.0 and prompt everyone using it to upgrade? For people running servers and browser developers, the best advice from Google is to support TLS_FALLBACK-SCSV. Put simply, stop accepting SSL connections and only accept those on TLS.

Right now, Google says that it’s working on changes to Chrome to prevent it from falling back to SSL. Other browser developers may follow suit.

My best advice to you is to keep your browser up to date and make sure you don’t go to sites that you don’t trust. Other than that, you can also email website administrators with your concerns and link them to this article.

Any Other Helpful Advice?

If you think you have something helpful to add to this discussion, please go ahead and leave it in a comment! Everyone needs to be aware of everything they can do to maintain the security of all their information when browsing the Web.

How to Compose A New Email Directly From Your Browser [Quick Tips]

Regardless which email client you are using, when you need to compose an email, you will always need to switch to your email client and click the “Compose” button. Here is a neat trick for you to compose a new email directly from your browser.

4 Reasons Why A Third Party DNS Server Is Better Than What Your ISP Gives You

You’ve probably heard of alternate DNS servers and how they could probably help you in some way or another. You may also wonder why you need to switch over. I’m going to give you some reasons why you probably should be using third party DNS server. You will end up wondering why you haven’t done it yet.

3 Ways to Allow Guest Users on Google Chrome

If you’re using Chrome and don’t feel like letting people poking into your privacy, here are some ways to set up guest users account in Google Chrome.

9 Ways to Make Better Use of Gmail Filters

Gmail filters is a good way for you to organize your inbox without you doing the manual work. Here are a few ways that you can make good use of Gmail fliters.

Is Your Email Provider Leaking Your IP Address to Recipients? Here’s How to Find Out

If you care about your privacy, you need to make sure that your email provider is not leaking your IP address to recipients. Here’s the tool for the job!

How Does ICANN’s Relationship with the US Affect You?

You’ve probably heard on the news something about ICANN and its “cozy relationship with the United States.” So how does that affect both you and me?

Hacked: 11 Signs Your Online Security Is Being Compromised

When you start to see weird behavior on your PC, it could be signs that your online security has been compromised. Here are 11 signs you should take note of

How to Know the Word Count of Any Text in Firefox

For those who need to keep track of word count, Word Count Tool for Firefox allows you to easily find out the word/character count of highlighted text in the browser.

How to Get Rid of the Stickers in Comments on Facebook

Facebook added the sticker feature in its comments section. For those who dislike it, you can disable stickers in Facebook comments in Chrome and Firefox.

How Anonymous Are You on the Internet, Really?

If you really want to be anonymous on the web, here are a few things you got to know and also learn a couple of tenets.

How to Enable Timed Website Blocking In Firefox

There are many distractions in the Web. PomodoroFox for Firefox lets you blocks unproductive websites that you specify and be more productive.

Should You Back Up Physically or On The Cloud?

Between backing up your files physically in external hard disk and the cloud, which one is better? Let’s find out in this article.