© Crimson, fotolia.com

© Crimson, fotolia.com

News for Admins

Tech News

Article from ADMIN 32/2016
By
News for system administrators around the world.

90% of All SSL VPNs are Insecure

Security firm High-Tech Bridge has conducted a statistical study that indicates 90% of all SSL-based VPNs in the world use insecure or outdated encryption. The study scanned 10,436 randomly selected, publicly accessible VPN servers taken from a scope of 4 million randomly selected IPv4 addresses. The results shows the following issues:

According to the study, only 3% of the sites were compliant with Payment Card Industry Data Security Standard (PCI DSS) requirements, and none were compliant with the US National Institute of Standards and Technology (NIST) guidelines.

The sobering study indicates that, after so many security alerts and news posts, organizations around the world are still not fully aware of the problems associated with older versions of SSL. See the blog post at the High-Tech Bridge site https://www.htbridge.com/blog/90-percent-of-ssl-vpns-use-insecure-or-outdated-encryption.html for more information, and definitely upgrade your SSL/TLS service and spend some time with your VPN implementation to make sure the service is up to date.

Dangerous New Attack Could Compromise One Third of All HTTPS Servers

A team of security researchers has uncovered a high-severity new attack that could make up to one third of all HTTPS web traffic vulnerable to compromise. The cross-protocol DROWN attack (CVE-2016-0800)

...
Use Express-Checkout link below to read the full article (PDF).

Buy this article as PDF

Express-Checkout as PDF
Price $2.95
(incl. VAT)

Buy ADMIN Magazine

SINGLE ISSUES
 
SUBSCRIPTIONS
 
TABLET & SMARTPHONE APPS
Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content

comments powered by Disqus