Security @ Opera

How secure is the secure web? SSL/TLS-server stats, part 2

, , , , , , ,

It's about time for an update on the status of renego-patched servers across the Web. Our "TLS prober", as introduced a few weeks ago, has been regularly checking which secure servers support the renegotiation protocol every week since late February. We have seen a slow and steady increase over the last weeks, and, on our last run, done this week, the share of servers that were patched was just over 12%, at 12.1%. A good cause for a celebration! party



We are a bit worried that the growth is not going faster than this, though. It even seems to have slowed down a bit. If the growth continues at the same pace, or slower, this means that all servers will not be patched earlier than the end of 2011. This is far too long for a potential security hole to be in the wild, in our opinion. We currently do not have a good overview of which of the big vendors are responsible for most of the unpatched servers, but we will definitely look into this and do what we can to push for faster patching.

Something else worrying we have discovered is that the majority (around 80-90%) of the patched servers have spec-violations in how they have implemented the renegotiation patch (or rather, the renegotiation extension).



Yngve has more details on the issue in a new article, and we are contacting those vendors that we have clearly identified as having implemented non-compliant patches.

We're also looking into some of the other specs of the servers we test. One of the things we have been interested in is the cipher suite using MD5 (128 bit ARC4-RSA/MD5). Since this cipher suite is expected to become significantly weaker soon, as mentioned earlier, we want to disable it soon. We have even been contacted by users who are wondering why we still support this cipher suite. First though, as with the renegotiation issue, we have to know how many servers this will affect i.e., how many servers support only this cipher suite. According to our "TLS prober", around 1% of servers accept only this cipher suite. This is a sizable portion of servers, and even includes at least some important online payment services (!), so we will have to wait a bit longer before we disable this cipher suite.

Do you have any ideas on how to make server owners patch their servers faster? Let us know in the comments!

How secure is the secure web? SSL/TLS-server stats, part 1How we rate security issues

Comments

setsutekh Wednesday, June 2, 2010 4:04:16 PM

So when will Opera's servers be patched?

Yngve Nysæter Pettersenyngve Wednesday, June 2, 2010 4:08:59 PM

When the OS distribution(s) gets patched, I am told.

Charles SchlossChas4 Wednesday, June 2, 2010 6:00:45 PM

Do you have any ideas on how to make server owners patch their servers faster



There is the issue of threat in most countries data loss is supposed to be stopped by the company, and having bad security could cause a credit card sniffing (steal the # and stuff) so who would want to be the site blamed for not being able to keep the site safe from sniffer and hackers?

The TJMax thing was big as the security for the card terminals was not secure and that lead to a couple GB of credit card data being sniffed right over the air, so I don't think they want to be blamed for failing to protect their users sensitive data, on a spec-violation.

leomajko Wednesday, June 2, 2010 6:41:50 PM

Just contacted my two banks (which does not support TLS renegociation, and one even uses MD5) to inform them on the issue. Hope they can correct that soon.

Cutting Spoonhellspork Wednesday, June 2, 2010 7:17:24 PM

Banks: Not big on security.

Nelson BMisterSSL Wednesday, June 2, 2010 10:23:37 PM

> how to make server owners patch their servers faster

Turn up the heat in steps.

1. Put an image like this in the status bar while viewing their site. Let it be a link to some page that explains how they (the site admins) can fix their servers to eliminate this.
http://madsenworld.dk/anigif/bars/rfirewal.gif

2. When they ignore that, superimpose an image like this over their site while viewing it.
http://images2.layoutsparks.com/1/146686/my-nightmare-burning-fire.gif

3. Get the other browsers to do likewise.

Artur „Jurgi” JurgawkaJurgi Thursday, June 3, 2010 8:59:55 AM

There was once an iniiative „Web Donkeys” (http://osiolki.net/) in Polish internet, condemning badly written sites, especialy IE-only. They have done a lot of good. Something like that would be helpful.

Cutting Spoonhellspork Friday, June 4, 2010 6:05:42 PM

A network news special would be great: "Do our banks actually care about security??"

Thomas PikeXiven Monday, June 7, 2010 2:42:58 PM

Do you have any ideas on how to make server owners patch their servers faster


Convincing the Debian and Ubuntu teams of the importance of patching this properly (rather than the half-patch they have done for the current stable releases) would be a very big step. Currently there is no stable Debian or Ubuntu release using a new enough version of openssl, making it extremely difficult for server admins to upgrade even if they should want to.

Cutting Spoonhellspork Monday, June 7, 2010 4:47:24 PM

Yeah Debian may be open, but they assuredly do not move fast.

For some banking sites, they probably use deprecated software that cannot be made to support newer security. After all it is cheaper than rewriting the program for a newer platform, and perhaps they'll reconsider if something bad happens.

Developed nations should set an adoption requirement for security; banks that can't keep up would be punished.

Charles SchlossChas4 Monday, June 7, 2010 8:37:46 PM

Originally posted by hellspork:

For some banking sites, they probably use deprecated software that cannot be made to support newer security. After all it is cheaper than rewriting the program for a newer platform,


Yep it is true I saw a banking site that gave me when I used Opera 10 saying the it is not greater than version 4 (this was about 3 months ago)

Cutting Spoonhellspork Tuesday, June 8, 2010 4:58:42 PM

I've mentioned before, but do you remember when they discovered a three-year-old flaw in Debian's ciphering engine? All keys generated by Debian, Ubuntu and their relatives, had only 2^15 possible values (based on process ID only), and could be narrowed within a few hundred possible values. It affected any computer or device which used such keys for authentication or encryption. It was a nightmare.

Charles SchlossChas4 Wednesday, August 11, 2010 4:50:48 AM

This related?
Microsoft Security Advisory (977377)
http://www.microsoft.com/technet/security/advisory/977377.mspx

Yngve Nysæter Pettersenyngve Wednesday, August 11, 2010 9:45:48 AM

More precisely: http://www.microsoft.com/technet/security/bulletin/MS10-049.mspx

And it will be interesting to see what happens to the patch rate the next few weeks.

Cutting Spoonhellspork Wednesday, August 11, 2010 10:32:39 PM

There should be laws to protect banks from their own budget offices, the IT needs to be continually developed and updated.

Write a comment

You must be logged in to write a comment. If you're not a registered member, please sign up.