IBM Blocks ‘Bar Mitzvah’ Attack In SSL/TLS
April 27, 2015 Alex Woodie
IBM recently issued a security bulletin for a newly discovered security vulnerability–a weak cryptography algorithm in the SSL/TLS protocol stack–that could allow hackers to steal data. That vulnerability was dubbed the “Bar Mitzvah Attack” by the security researcher who discovered it because it uses a 13-year-old weakness in the RC4 algorithm. The Bar Mitzvah flaw was first described by Itsik Mantin, director of security research with Imperva, at the Black Hat Asia security event held in Singapore last month. The attack stems from a weakness in the way that the RC4 stream cipher creates encryption keys, which could allow |