ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    What is POODLE and how do I protect myself?

    IT Discussion
    poodle webroot
    5
    5
    2.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RichardR
      Richard
      last edited by

      **What is POODLE?
      **
      POODLE stands for Padding Oracle On Downgraded Legacy Encryption. What that means in practical terms is that there is a vulnerability in the SSLv3 communication protocol that allows for man-in-the-middle attack on secure HTTP connections

      **Can you repeat that in English?
      **
      This vulnerability can allow a compromised WIFI hotspot or ISP to snoop on your secure connections. A man in the middle attack is like the game of telephone with three people, and the person in the middle is the bad guy. He or she intercepts encrypted communications and can decrypt them to snoop passwords or other confidential data. For instance if you are doing online banking then a malicious man-in-the-middle could get your password and other confidential data transmitted.

      **When will this be fixed?
      **
      There is currently no fix or patch for this vulnerability. SSLv3 is an older version of the HTTPS protocol, and is only used for compatibility for older browsers and has been replaced by the newer TLS 1.0 protocol.

      **How can I protect myself and my users?
      **
      Make sure you and your users are using an up to date browser, and turn off SSLv3 for your browser. Here are instructions for Internet Explorer and Chrome, and here are instructions for Firefox. You can share these instructions to your users as well.

      This page will also tell you if SSLv3 is on or off in your browser to confirm that you've disabled it.

      For server side checking, you can go here: https://zmap.io/sslv3/.

      For the lighter side, here is our movie idea we are pitching.

      poodlenado.jpg

      1 Reply Last reply Reply Quote 6
      • scottalanmillerS
        scottalanmiller
        last edited by

        Good info, thanks!

        Now get on producing that movie!

        1 Reply Last reply Reply Quote 1
        • Reid CooperR
          Reid Cooper
          last edited by

          Great. When do we get a link to the movie? 😉

          1 Reply Last reply Reply Quote 1
          • thanksajdotcomT
            thanksajdotcom
            last edited by

            Good explanation, and better picture! Thanks for sharing!

            1 Reply Last reply Reply Quote 0
            • StrongBadS
              StrongBad
              last edited by

              Thanks.

              1 Reply Last reply Reply Quote 0
              • 1 / 1
              • First post
                Last post