The DnD Sanctuary

Pings => Otter Browser Forum => Topic started by: djgl on 2015-05-22, 16:24:20

Title: Logjam Attack
Post by: djgl on 2015-05-22, 16:24:20
Found this link on another forum.

It appears that Otter (72) is vulnerable to this attack assuming that the test is correct.

Quote
Warning! Your web browser is vulnerable to Logjam and can be tricked into using weak encryption. You should update your browser.


https://weakdh.org/

Title: Re: Logjam Attack
Post by: ersi on 2015-05-22, 16:39:01
Affects also Qutebrowser and Seamonkey, while DWB, Luakit and old Opera are unaffected. I have no idea how the test works or what it even tests.
Title: Re: Logjam Attack
Post by: py-thon on 2015-05-23, 19:46:57
Background information for those interested:
http://blog.cryptographyengineering.com/2015/05/attack-of-week-logjam.html (english)
http://www.heise.de/security/meldung/Logjam-Attacke-Verschluesselung-von-zehntausenden-Servern-gefaehrdet-2657502.html (deutsch)
Title: Re: Logjam Attack
Post by: Emdek on 2015-05-25, 13:47:36
I've disabled affected ciphers in default set:
https://github.com/OtterBrowser/otter-browser/commit/f06de364bb724c573ca52fb8cd6554207183b3a8
Title: Logjam Attack
Post by: yarickpn on 2015-07-13, 06:47:04
I dont think he has the attack values set yet?
Title: Re: Logjam Attack
Post by: py-thon on 2015-07-13, 11:48:58
He said he has and that's why using current otter versions on https://weakdh.org/ will tell you "Good News! Your browser is safe against the Logjam attack." .