Yesterday morning we told you about a rumored bug in an older encryption protocol, SSL 3.0. Today the details of this bug were released and although it looks bad, it might not be as big as first hinted. The bug has been called Poodle (Padding Oracle On Downloaded Legacy Encryption) and has sparked many articles with clever lines about dogs and biting people… For all of that nonsense this is not something that is going to go away and highlights a major issue in how we communicate over the internet.
The words anonymity, privacy and security go hand in hand… in hand. Although the term anonymity is often seen as a bad thing by law enforcement and policy makers the truth is that it is a critical part of the security chain and is something that needs to be addressed in the way communications happen over the internet. Simply put, how can an attacker get to you if they do not know where you are coming from? Anonymity is a form of security that is in common use by the “red” team so why not put this to use in protecting the green?