Heartbleed 2: OpenSSL Shows More Security Flaws
Companies still patching computers that contain theHeartbleed bug now have to contend with other flaws found in the OpenSSL encryption protocol that secures data flowing between PCs and Web servers. The latest bugs in the open-source OpenSSL cryptography library include one that would let an attacker eavesdrop on traffic between a client and server. So-called man-in-the-middle attacks typically involve the hacker decrypting and modifying traffic to manipulate the data flow to his own benefit, such as stealing credentials to online services. The latest flaw is less of a risk than Heartbleed,…
Read More