HomeCyber SecurityIs your browser in the Goldilocks zone?

Is your browser in the Goldilocks zone?

Date:

So most corporates will need to make sure their browsers are just right – the Goldilocks zone – not too weak, but not too secure.

There are two pesky algorithms at the bottom of this: SHA1 and RC4.

- Advertisement -

SHA1

SHA1 is a hashing algorithm used in TLS connections; but it has been known for a while that with increases in computing power, it is weak. It has been replaced with SHA256, commonly SHA2 for short. This is good, however, it leaves a legacy to deal with.

Some web sites still operate with SHA1 certificates (one million sites according to Netcraft). This is particularly a problem with bespoke corporate applications running on internal web sites.

Come January 1st, 2017, an increasing number of browsers, including the latest releases from Microsoft, Firefox and Chrome will simply not accept SHA1 certificates. These sites will be cut off from new browsers.  (Microsoft have also hinted this date could come forward to June 2016).  Chrome is already showing warnings to users accessing SHA1 sites.

You could use an old browser (not recommended due to known vulnerabilities, etc). However, if you use a browser that is too old, it will not be able to handle SHA2. So new sites running SHA2 only will be cut off from old browsers.

- Advertisement -

The following graphic from Cloudflare gives a useful summary:

goldilocks zone browser

RC4

SHA1 is not the only issue, the RC4 cipher is deprecated too, and browsers are withdrawing support. This has fewer potential implications, but legacy, bespoke in-house applications could have an issue.

How did we get here?

We’ve known for many years that we must patch, and keep software up to date, to mitigate malware.  We’ve known that using TLS is good to maintain our privacy, but we seem to have overlooked the details of exactly how those TLS connections are working.

While most commercial services are migrating for latest algorithms, many bespoke / internal applications have become left behind, and it is these services that are likely to be the cause of headaches as browsers refuse to access SHA1.

We have similar issues with SSL migration too.  We know SSL is insecure, and you should be using TLS.

What should you do?

First and foremost, you should use a current, fully patched browser for accessing anything on the Internet. The malware/ransomware risk of old browsers is just too high to use anything less.

My recommendation is you take an audit of all the business critical applications using TLS, and determine which use SHA1. At the same time hunt down anything using SSL.

Then plan to upgrade these (where possible) to using SHA2, by December 31st, 2016 at the latest and if not before. Where this is not possible you need to determine dual-browser strategies.

- Advertisement -

Related articles:

Boost Your Career: Top 5 Computer Security Courses for Aspiring Cybersecurity Professionals

Discover the top 5 computer security courses to kickstart your cybersecurity career. Learn essential skills and gain certifications to protect digital assets.

Securing the Cloud: Best Practices for Cybersecurity in Cloud Computing Environments

Discover essential cybersecurity practices for cloud computing environments. We explore how to safeguard your data and infrastructure in the ever-evolving digital landscape.

Learning Through Play: 7 Cybersecurity Games That Sharpen Your Hacking Defense Skills

Discover 7 engaging cybersecurity games that make learning fun while boosting your hacking defense skills. We explore how these cyber security games sharpen your expertise.

The Backbone of Cybersecurity: A Deep Dive into Modern Network Security Practices

Discover how network security in cyber security protects organizations from threats. Learn about firewalls, encryption, and best practices for safeguarding digital assets.

5 Critical IT Security Threats You Can’t Afford to Ignore

Discover the top 5 IT security threats that could put your business at risk. Learn how to protect your data and systems from these critical vulnerabilities.

13 COMMENTS

    • Oh, another self-proclaimed expert advocating for immediate change without considering the practicality or implications. Encryption algorithms aren’t just swapped overnight, pal. Educate yourself before blindly calling for upgrades. #RealisticApproach

    • RC4 may not be in vogue, but let’s not assume everyone is living in the world of bleeding-edge tech. Some people may have genuine reasons for not upgrading browsers, so a little empathy won’t hurt.

    • Nah, no need for an upgrade. Just use common sense and avoid sketchy websites. It’s not rocket science. Plus, who has time to worry about browser security? Live a little and stop being so paranoid.

    • Wow, it’s surprising how some people are still stuck in the past. SHA1 and RC4 are outdated and insecure, so upgrading is a no-brainer. It’s time to prioritize security and leave the Goldilocks zone behind. Stay safe online!

    • Haha, I know right?! It’s amazing what you learn online. Next thing you know, we’ll be talking about browsers having favorite porridge temperatures. 🥣🔥 But hey, if it helps optimize my browsing experience, I’m all for it!

LEAVE A REPLY

Please enter your comment!
Please enter your name here