• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

The Poodle computer bug: The what, how, and why for business

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
November 12, 2014, 1:04 PM ET
Cyber security, piracy, hacker, bug, flaw, crack, skull
Cyber security, piracy, hacker, bug, flaw, crack, skullIllustration: DimaChe—Getty Images

By now you’ve probably heard of a new computer bug called Poodle. Sure, the name is adorable. (It really stands for the far less cute “Padding Oracle On Downgraded Legacy Encryption.”) It was discovered by Google researchers two months ago. And, most importantly, cyber security researchers have determined that it’s less serious than the Heartbleed (from April) and Shellshock/Bash (from September) bugs.

But “less” is a relative term. The flaw demands a fix.

What you can do about it

Here’s the download if you’re willing to get a bit technical. If the web browsers on your machines still support the long since deprecated encryption protocol Secure Sockets Layer (SSL) 3.0, which is intended to securely connect computers and web servers, disable it yourself. It’s 15 years out of date.

As for which browsers: If you’re using Google Chrome version 40, you’re in good shape—SSL 3.0 is disabled by default. Mozilla will disable the protocol by default in the next version of its browser, Firefox 34, which is due later this month. All versions of Microsoft’s Internet Explorer support SSL 3.0; that support needs to be disabled through the Options menu. And as for Apple’s Safari, the company’s security update 2014-005 mitigates the vulnerability while still allowing SSL 3.0.

Until you deactivate SSL 3.0, you might want to avoid connecting to public Wi-Fi networks. Otherwise sophisticated attackers occupying a privileged position on your network may be able to intercept your data, steal your passwords and browser cookies, and masquerade as you on websites, allowing them to hijack your accounts.

“In terms of security, when a protocol becomes deprecated that’s about the time you say we need to get off this and get off this soon,” says Waylon Grange, a senior malware researcher at Blue Coat, a Sunnyvale, Calif. cyber security firm. “It means a vulnerability or weakness has been found and people know it can be attacked.”

In the world of encryption, a newer, more secure protocol, Transport Layer Security (TLS) 1.0, replaced SSL 3.0 in 1999. Since then, there have been two updates—TLS 1.1 in 2006 and TLS 1.2 in 2008. Another, TLS 1.3, is in the works.

“This is almost four versions now,” Grange adds, “at some point you need to say, ‘Let’s move up.’”

How we got here

Some businesses may not wish to retire older protocols like SSL 3.0 since they want to ensure they can connect with every last potential customer. That means accommodating people who have not updated their browsers in eight years, when Internet Explorer 7 enabled TLS 1.0 support by default. “Do you really want those guys still on your networks?” Grange asks, noting that their machines are likely vulnerable to a host of other flaws—and adding that SSL 3.0 transactions represent less than one percent of all web traffic.

“If a machine is vulnerable with this, it’s likely to have other vulnerabilities because it’s that old,” Grange says. “It’s putting your whole network at risk because of this ancient technology.”

Then again, retaining older protocols like SSL 3.0 also provides a fallback option for browsers should connection attempts by newer protocols not work, for whatever reason—an if-all-else-fails approach. The problem is that savvy hackers can sit on a network, scramble communications, and frustrate a machine’s attempts to connect with a server, forcing it to fall back on an outdated protocol. The hackers perpetuating this type of attacks, referred to as man-in-the-middle, can then implement Poodle and steadily decrypt transacted sensitive information.

Hugh Thompson, chief security strategist at Blue Coat, says companies should retire SSL 3.0 as soon as possible, even if they’re unsure what old devices relying on it may still be connected to their networks. If a browser embedded in a printer has no update option, “it may just be time to get rid of that printer,” he says.

Forgotten, outdated devices are bound to have issues, he says. “Almost certainly something will stop working.” Nevertheless, “You should definitely deprecate it,” he says. “It’s definitely worth it.”

What to take away from the incident

Disabling SSL 3.0 is not the only lesson to be learned from Poodle. Consider the bigger picture: In the past year, three high-profile bugs have rocked the business world.

In April, the web was hit by Heartbleed, a frighteningly pervasive encryption vulnerability. Five months later we were shocked by Shellshock, a slightly less worrisome bug (because it poses more of a technical challenge to hackers) yet one that bore grave implications (like the ability of a hacker to take over machines). Now we have Poodle—and more bugs are bound to surface.

As Internet companies begin to encrypt more traffic across the web, attackers are going to become even more interested in finding cryptographic weaknesses. Businesses must learn to cope, Thompson says.

“If you thought Heartbleed was the equivalent of a meteorite hitting a data center,” Thompson says, “you would do everything you could to clean up from the meteorite. But you wouldn’t have set up some big meteorite cleaning processes. These three signal that this is not a rare event. If that’s the case, there is a need to be able to build up a set of competencies around failure.”

That means putting in place agile response teams, building network forensic capabilities and updating to new versions of software and protocols in a timely manner. It’s a matter of setting up the right processes and practicing good network hygiene, Thompson says. There is no excuse to be caught unaware–especially if, in the end, it appears your company is more concerned with backward compatibility than security.

Next, read: “How Home Depot CEO Frank Blake kept his legacy from being hacked” by Jennifer Reingold.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in

Nutrafol Review 2026: Ingredients, Cost, and Whether It Works
HealthDietary Supplements
Nutrafol Review 2026: Ingredients, Cost, and Whether It Works
By Christina SnyderApril 1, 2026
42 minutes ago
Ayesha and Stephen Curry
C-Suitephilanthropy
Warren Buffett revives his legendary charity lunch auction—this time with Stephen Curry. His last one raised $19 million
By Jacqueline MunisApril 1, 2026
43 minutes ago
Lean In’s new 25-year-old CEO has a plan to close the AI gender gap
NewslettersMPW Daily
Lean In’s new 25-year-old CEO has a plan to close the AI gender gap
By Emma HinchliffeApril 1, 2026
49 minutes ago
A person looking at their phone and computer in a kitchen.
Bankingchecking accounts
New bonus alert: HSBC Premier checking offering up to $5,000 bonus (for a limited time)
By Joseph HostetlerApril 1, 2026
50 minutes ago
Luigi Mangione’s federal trial has been pushed back to October in killing of UnitedHealthcare CEO
LawMurder
Luigi Mangione’s federal trial has been pushed back to October in killing of UnitedHealthcare CEO
By The Associated Press, Michael R. Sisak and Larry NeumeisterApril 1, 2026
1 hour ago
A chip research center site operations manager stands next to a window overlooking the facility.
EnvironmentData centers
Data centers are so hot, their ‘heat island’ effect is raising temperatures up to 6 miles away and impacting 343 million people worldwide, study finds
By Sasha RogelbergApril 1, 2026
1 hour ago

Most Popular

Jerome Powell says the $39 trillion national debt is ‘not unsustainable,’ but warns the trajectory ‘will not end well’
Economy
Jerome Powell says the $39 trillion national debt is ‘not unsustainable,’ but warns the trajectory ‘will not end well’
By Fortune EditorsMarch 30, 2026
2 days ago
Markets cheer as Trump threatens to abandon Iran war, but Jamie Dimon sides with allies: ‘Win this thing and clean up the straits’
Energy
Markets cheer as Trump threatens to abandon Iran war, but Jamie Dimon sides with allies: ‘Win this thing and clean up the straits’
By Fortune EditorsMarch 31, 2026
1 day ago
Kevin O'Leary says if you earn $68,000 a year and follow this rule, you'll retire a millionaire
Personal Finance
Kevin O'Leary says if you earn $68,000 a year and follow this rule, you'll retire a millionaire
By Fortune EditorsMarch 31, 2026
1 day ago
A man used AI to call 3,000 Irish bartenders to track the cost of Guinness. Now pubs are lowering their prices to compete
AI
A man used AI to call 3,000 Irish bartenders to track the cost of Guinness. Now pubs are lowering their prices to compete
By Fortune EditorsMarch 30, 2026
2 days ago
Two-thirds of parents say their adult Gen Z kids still rely on them financially  for support—even though it's putting them under strain
Success
Two-thirds of parents say their adult Gen Z kids still rely on them financially  for support—even though it's putting them under strain
By Fortune EditorsMarch 31, 2026
1 day ago
Hiring just hit a level not seen since the economy was ‘closed down literally’ during COVID, top economist says
Economy
Hiring just hit a level not seen since the economy was ‘closed down literally’ during COVID, top economist says
By Fortune EditorsMarch 31, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.