Secure web sites attacked via SSL

A previously theoretical attack against secure web sites will be proven possible later this week. SSL/TLS protects sensitive data transmitted between your computer and secure websites such as your bank and Gmail. Researchers have found a way to decrypt the encrypted SSL traffic, allowing them access to the sensitive data inside.

For the moment the best protection is to use a JavaScript blocker like NoScript, which will prevent the Javascript from running on unauthorized sites. Note that this attack hasn’t been seen in the wild yet, but it’s probably only a matter of time.

http://www.theregister.co.uk/2011/09/19/beast_exploits_paypal_ssl/

http://noscript.net/