New Poodle Bug Revealed by Researchers

Editorial Note: Talk Android may contain affiliate links on some articles. If you make a purchase through these links, we will earn a commission at no extra cost to you. Learn more.

Vicious PoodleLook out! Three Google researchers published a bug today, causing much of the internet to panic over securing systems. The bug is called POODLE, for “Padding Oracle On Downgraded Legacy Encryption.” Poodle bypasses SSL protections, much like last year's dreadful HeartBleed, causing some to call it “PoodleBleed.”

Data in transit between a website and a user is protected by SSL, usually seen in the url as a green padlock. However, if compromised, a hacker can intercept data in transit, opening the door to all kinds of technical tomfoolery. Fortunately, POODLE targets SSL 3.0, which is 15 years old, but a few systems still use it. If a system uses 3.0, it seems disaster can be averted by upgrading—and quickly!

Source: The Verge

Total
0
Shares
1 comment
  1. 60% of my spam is from compromised accounts which seem to trace to Mobile devices that are used in Hotspots, public Wi-Fi, this makes this attack a real problem.
    No idea how to disable SSL3 and revert to SSL2 on my Samsung Note 2?

Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

TalkAndroid Daily Dose for October 14, 2014

Next Post

Google Play Store downloads beat out iOS App Store downloads in volume by 60%