Skip to main content

Logjam HTTPS exploit downgrades security to get at your data

researchers discover new https flaw but thankfully its easy to patch logjamhttpsheader
Dorn1530/Shutterstock
It seems like every day a new vulnerability is discovered in some Web protocol, and now researchers claim they’ve identified another. Logjam is a hole in the Diffie-Hellman key exchange protocol, a commonly used method of establishing a secure connection. It takes a bit of work to exploit, but with the right access, the bug can potentially spill sensitive data all over the place.

The Logjam exploit starts with a man in the middle attack. Whoever is seeking to access data with Logjam puts themselves between a user and the server, but continues to pass messages back and forth, picking them up on the way. Most modern servers use long algorithms to prevent anyone who isn’t on each end from un-encrypting the data, but the attacker can tell both the client and the server to lower the security level, turning that long algorithm into an easily hacked 512-bit prime number.

Once the 512-bit prime number, a relatively weak encryption method, is unlocked, the attacker has access to any data sent or received between the server and client. They might not even need to turn it down as low as 512 bits, since some research shows that national powers may already have the technology required to crack 768 and 1,024-bit prime numbers.

Thankfully, the fix for Logjam is a relatively simple one, and updates are already rolling out that take care of the issue. Most end users won’t need to do anything except update their browser to the latest version, which is always a good idea, anyway. If you’re running a server, either application or email, you just need to makes sure you’ve updated any libraries or applications you’re using.

If you’re still worried you might be vulnerable, there’s a handy page that will tell you whether your browser is safe or not.

Brad Bourque
Former Digital Trends Contributor
Brad Bourque is a native Portlander, devout nerd, and craft beer enthusiast. He studied creative writing at Willamette…
Update your Windows PC now to fix this critical PrintNightmare security flaw
Person sitting and holding Dell XPS 13 laptop on their lap.

You might have heard the news about "PrintNightmare," a vulnerability in the Windows Print Spool service that could leave hackers in control of your PC under certain conditions. After raising concern about it, Microsoft has officially issued a patch that resolves the issue and the company urges all Windows users to install it as soon as possible.

Though unrelated, Microsoft is also aware of a separate issue raised on July 16 relating to the spooler service that is yet to be patched and is working on a separate fix, coming later. This involves local (physical) access to a PC and potentially allowing hackers to install programs and view, change, or delete data via the spooler service.

Read more
Elon Musk promises Tesla app will soon get an important security feature
2017 tesla model x p100d review  30

Tesla boss Elon Musk has said on a number of occasions that two-factor authentication is coming to the Tesla app, but car owners are still waiting.

Responding recently to a customer inquiry asking if it will ever land, Musk acknowledged that the absence of the security measure is somewhat surprising for a company of Tesla’s status.

Read more
Andrew Yang’s Data Dividend Project wants you to get paid for your data
Andrew Yang

Former presidential candidate Andrew Yang wants everyone to get paid when companies use their personal data. 

Yang appeared on Digital Trends Live on Thursday to talk about the Data Dividend Project, which he recently founded to encourage people to take control of their online data. 

Read more