Blog

SSL - 1440x460

Is your website running SSL v3.0?

Earlier this week, Google announced a serious exploit which affects all webmasters and users of SSL v3.0. This security vulnerability is a serious issue because out of Alexa’s top one million domains, 96.9 per cent support SSL v3.0.

The attack, which has been coined POODLE, can take advantage of web browsers’ fall back to SSL v3.0. Google has announced that the solution is to turn V3.0 support off, commenting that in the coming months they will disable SSL 3.0 support completely from their product line:

“Disabling SSL 3.0 support or CBC-mode ciphers with SSL 3.0, is sufficient to mitigate this issue, but presents significant compatibility problems, even today. Therefore our recommended response is to support TLS_FALLBACK_SCSV. This is a mechanism that solves the problems caused by retrying failed connections and thus prevents attackers from inducing browsers to use SSL 3.0. It also prevents downgrades from TLS 1.2 to 1.1 or 1.0 and so may help prevent future attacks.”

So what can you do?

Internet Users:

Although browsers will make these updates in the near future, users can disable the use of SSL v 3.0. Those users who want to prevent being exploited through POODLE should disable the use of SSLv3 within your web browser. The below shows how this can be done for each of the most common web browsers:

 

Google Chrome (please note that this will only protect if you open Google Chrome from the shortcut on your desktop).

  1. Right click the Google Chrome shortcut on your desktop
  2. Click properties from the drop-down menu
  3. On the properties menu, click inside the ‘Target’ box and scroll all the way to the right past the quote (‘))
  4. Simply enter –ssl-version-min=tls1
  5. Click OK and continue with administrator permissions

Mozilla Firefox

Mozilla advises users that the safest way is to ensure that Firefox is configured to automatically update. Under ‘Preferences / Advanced / Update, and make sure that ‘Automatically install updates’ is checked.

For users who wish not to wait until SSL v3.0 is disabled by default should follow this guide

Internet Explorer

  1. Launch internet options from the Start Menu
  2. Click ‘Advanced’ and uncheck ‘Use SSL v3.0’
  3. Click OK

123-reg response

We take security vulnerabilities of this kind very seriously and as a matter of course we have disabled SSL v3 protocol support. Customers are advised to configure their web browser to disallow communications over SSL v3.0. Customers should upgrade to their latest browsers editions to continue using www.123-reg.co.uk

Of course, we are always here to advise and help so if you do have a questions regarding this, simply get in touch here.

123-reg has disabled SSL v3.0 on our website.

 

Find your perfect domain name today

Edit Template

In this article

Now more than ever, social media is essential for online business success. Studies show that a quarter of UK brands now see socials as their top sales channel, ahead of email marketing and...

How many times do the same people visit your website? Unless you have an online shop, there’s no reason for a prospect to visit your site more than once or twice. Once they...

How does this sound: sipping espresso at a café in Milan one week, lounging at a beachside bar in Bali the next, perhaps a few days in Singapore after that — all the...

Launched in 2016, TikTok became a tremendous success on the social media scene by offering users the ability to post short-form videos. Far from a short-lived fad or gimmick, TikTok today boasts over...