The Logjam Attack

General discussion about Slimjet, or other issues related to web browser in general.
Locked
reactorr
Posts: 68
Joined: Sat Mar 21, 2015 2:45 pm

The Logjam Attack

Post by reactorr »

Slimjet Browser Version 4.0.6.0
Warning! Your web browser is vulnerable to Logjam and can be tricked into using weak encryption. You should update your browser.

https://weakdh.org/

webgaldom
Posts: 6
Joined: Mon Apr 27, 2015 6:05 am

Re: The Logjam Attack

Post by webgaldom »

See my new post about the Logjam mitigation (fix) for Slimjet.

viewtopic.php?f=5&t=339#p1654

galdom :idea:

reactorr
Posts: 68
Joined: Sat Mar 21, 2015 2:45 pm

Re: The Logjam Attack

Post by reactorr »

please update new version

webgaldom
Posts: 6
Joined: Mon Apr 27, 2015 6:05 am

Re: The Logjam Attack

Post by webgaldom »

reactorr wrote:please update new version
Slimjet authors are fixing the issue, an easy but temporary fix is possibile, just read the following post:

viewtopic.php?f=5&t=339#p1654

webgaldom

slimjetfan99
Posts: 2
Joined: Wed Sep 16, 2015 10:47 pm

Re: The Logjam Attack

Post by slimjetfan99 »

Will this be fixed in Slimjet 5?

reactorr
Posts: 68
Joined: Sat Mar 21, 2015 2:45 pm

Re: The Logjam Attack

Post by reactorr »

slimjetfan99 wrote:Will this be fixed in Slimjet 5?
YES

for test: https://weakdh.org/

analogfred
Posts: 17
Joined: Mon Jun 15, 2015 9:28 pm

Re: The Logjam Attack

Post by analogfred »

I just updated to 5.0.4.0 release and that web page says its still vulnerable

reactorr
Posts: 68
Joined: Sat Mar 21, 2015 2:45 pm

Re: The Logjam Attack

Post by reactorr »

wtf! you are right!

" Warning! Your web browser is vulnerable to Logjam and can be tricked into using weak encryption. You should update your browser. "

bksening
Posts: 14
Joined: Mon Oct 13, 2014 3:27 am

Re: The Logjam Attack

Post by bksening »

The Logjam attack fix will only come with update based on Chromium 45. (Unless SJ backports the DH key-size fix.)

dev
Posts: 761
Joined: Mon Apr 21, 2014 10:30 pm

Re: The Logjam Attack

Post by dev »

512-bit Diffie-Hellman is only used by a fraction of the Internet nowadays, its a 1970's protocol used for only a few years in secret, by UK GCHQ and the chrome 45 fix just uses 1024-bit DHE. Not something to worry about tbh.

Locked