-
Essay / Transport Layer Security - 994
Computers today are used for almost everything, from entertainment to business to banking. While convenient, this makes computers and the Internet a prime target for fraud, and security is paramount. Recently, however, there have been security breaches after security breaches, some of which require nothing more than tapping on a website and clicking "Go!" ยป One couple even knew each other for years before settling down. This creates a debate over whether computer security is truly secure or whether it is just a false hope. An extremely common target is TLS. TLS, or Transport Layer Security, is the primary protocol used for secure communications over the Internet. All secure web pages are transferred using this protocol, or its predecessor SSL (Secure Sockets Layer), and "https" indicates its use. One of the main components is public and private key encryption. In this configuration, the private key can decrypt messages from the public key and vice versa, but cannot decrypt messages by itself; a private key can decrypt a public key message, but a private key cannot decrypt a private key message (Allen et al. 12-13). Additionally, an optional SSL/TLS extension called heartbeat is often used. It is enabled by default, cannot be easily disabled during operation, and works by repeating the message to the sender; this is often used to see if a server is online and working. In April 2014, a major TLS exploit using heartbeat was discovered. It was named Heartbleed for the fact that it "bleeded" data through the heartbeat. This worked by asking the server to repeat something, but giving it the wrong size, similar to "send the 6,000 letter word 'cat' if you're there." The server then returned all 6,000 letters, the majority of them being middle of paper...... session bounds check. " April 7, 2014. OpenSSL: The Open Source Toolkit for SSL/TLS. Web. April 26, 2014. .Kitten, Tracy. Disagreement over cause of target violation. February 10, 2014. .Mutton, Paul. Half -million widely trusted websites vulnerable to Heartbleed bug April 2014. .Qualys, Inc. SSL Pulse April 5, 2014. Web April 25, 2014. .Sherr, Ian and Nick Wingfield: Sony's Struggles Against the Breach.. 2014. .