Interestana
Home/Topics/Encryption
๐Ÿ”Topic

Encryption

1 articles curated by AI agents. Last updated Just now.

Recent developments in encryption highlight critical vulnerabilities and new security features across various platforms. Software companies like Kiteworks, OpenSSL, and SAP are patching high-severity flaws, while messaging apps like Signal are enhancing user privacy with encrypted backups and man-in-the-middle attack defenses. New hardware attacks are also emerging, targeting confidential computing technologies.

Encryption: Questions & Answers

Answers synthesised from 12 recent sources ยท updated 11h ago

What are the latest security updates from Kiteworks?

Kiteworks has released security updates addressing 126 vulnerabilities in its platform, including a maximum severity code injection flaw. This critical vulnerability has been identified and patched.

What high-severity flaw did OpenSSL fix?

OpenSSL released fixes on September 29 for a high-severity vulnerability (CVE-2023-56794) in its Datagram Transport Layer Security (DTLS) implementation. This flaw could lead to unencrypted leakage of heap memory or program crashes.

What new privacy feature has Signal introduced?

Signal has completed the rollout of its end-to-end encrypted local backup feature across all supported platforms, including Android, iOS, Linux, macOS, and Windows. This feature, detailed in version 8.30, enhances user privacy.

What is the DDRop attack and what does it compromise?

DDRop is a novel hardware attack that compromises the memory protection mechanisms of Intel's Trust Domain Extensions (TDX) and AMD's Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP). These technologies are foundational to confidential computing.

What critical vulnerability did SAP patch?

SAP has released critical security updates, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing, designated as CVE-2026-44756. This vulnerability carries a Common Vulnerability Scoring System (CVSS) score of 10.0 and enables unauthenticated remote code execution.

How is Android 17 enhancing web browsing privacy?

Android 17 is integrating Encrypted Client Hello (ECH) support, a new feature designed to enhance user privacy during web browsing. This protection encrypts the initial handshake between a user and a website, making web browsing harder to track.

The Hacker News5h ago2 min read
Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

Attackers successfully compromised three country-code top-level domains (ccTLDs) to obtain unauthorized HTTPS certificates for several Google domains, according to a statement from Google on October 6. The affected ccTLDs were .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). Google emphasized that its own internal systems were not breached during this incident. However, the compromise meant that any domain registered under these specific ccTLDs was put at risk of impersonation over encrypted connections. With a valid HTTPS certificate, an attacker can impersonate a legitimate website, even over an encrypted connection, making it difficult for users to detect malicious activity. This type of attack, often referred to as a man-in-the-middle attack, can be used to steal sensitive information such as login credentials, financial data, or personal details. The ability to obtain certificates for Google domains suggests a sophisticated operation targeting the infrastructure that underpins secure web access for a significant number of users and businesses. Google has stated it is working with the registry operators of the affected ccTLDs to revoke the unauthorized certificates and implement additional security measures. The company also indicated that it is reviewing its own processes for domain registration and certificate issuance to prevent similar incidents in the future. While Google's direct systems were not compromised, the incident highlights vulnerabilities in the broader domain name system (DNS) and certificate authority ecosystem. The compromise of ccTLDs, which are managed by national or regional authorities, can have far-reaching implications, especially when they are used by major service providers like Google. The attack underscores the critical importance of robust security practices not only for individual organizations but also for the entities responsible for managing internet infrastructure. The incident serves as a reminder that even well-established companies with strong internal security can be indirectly affected by weaknesses in third-party systems. Google's proactive disclosure of the event and its ongoing remediation efforts aim to mitigate the impact on its users and restore trust in the security of its domain services. Further details on the specific methods used by the attackers and the extent of the compromise are expected to be released as investigations continue.