drown-attack-logo

A newly discovered hack attacked dubbed “DROWN Attack” could undermine security for millions of websites (DROWN stands for Decrypting RSA with Obsolete and Weakened eNcryption). DROWN is outlined to be a serious vulnerability that affects HTTPS and other services that rely on SSL and TLS (cryptographic protocols for internet security).

The DROWN hack/attack lets an attacker break the encryption that generally hides sensitive information like passwords and credit card numbers. Some notable sites vulnerable to the attack are Yahoo, BuzzFeed, StumbleUpon, and even Samsung’s website. Overall a third of internet websites are vulnerable to the attack, and only operators of these website servers can fix the security vulnerability–which is bad news for internet users looking for personal fixes.

The root of the attack comes from computer servers that support SSLv2 (Secure Sockets Layer version 2). It doesn’t matter if a current client uses a more recent protocol–if that protocol even allows SSLv2, then the threat remains.

When this protocol was created, the US government had it intentionally weakened so that other countries couldn’t improve their encryption standards. Professor Matthew Green from John Hopkins University explains that the issues stem from the “result of careless server configuration,” and that the “blame lies with crummy and obsolete embedded devices that haven’t seen a software update in years – and probably never will.”

Researchers looking to reproduce the attack did so under a minute since many of the servers that are vulnerable to the DROWN vulnerability are affected by other OpenSSL vulnerabilities (CVE-2015-3197 and CVE-2016-0703). Researchers concluded that an effective attack could be done in under 8 hours at a cost of $440.

While security vulnerabilities keep popping up, policymakers continue to try to press restrictions on cryptography to enhance national security. However, as seen in this case, reducing the strength of encryption can directly affect all of us.

TorGuard VPN is not vulnerable to the DROWN attack since it does not allow SSLv2 on our website, or VPN network. Our network security team remains vigilant in protecting TorGuard users against all security threats. Using a private VPN like TorGuard is not just mandatory in public Wi-Fi spaces, it is a must have if you’re looking to encrypt your internet to keep your private information – private.

Share this post