• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

The Poodle computer bug: The what, how, and why for business

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
November 12, 2014, 1:04 PM ET
Cyber security, piracy, hacker, bug, flaw, crack, skull
Cyber security, piracy, hacker, bug, flaw, crack, skullIllustration: DimaChe—Getty Images

By now you’ve probably heard of a new computer bug called Poodle. Sure, the name is adorable. (It really stands for the far less cute “Padding Oracle On Downgraded Legacy Encryption.”) It was discovered by Google researchers two months ago. And, most importantly, cyber security researchers have determined that it’s less serious than the Heartbleed (from April) and Shellshock/Bash (from September) bugs.

But “less” is a relative term. The flaw demands a fix.

What you can do about it

Here’s the download if you’re willing to get a bit technical. If the web browsers on your machines still support the long since deprecated encryption protocol Secure Sockets Layer (SSL) 3.0, which is intended to securely connect computers and web servers, disable it yourself. It’s 15 years out of date.

As for which browsers: If you’re using Google Chrome version 40, you’re in good shape—SSL 3.0 is disabled by default. Mozilla will disable the protocol by default in the next version of its browser, Firefox 34, which is due later this month. All versions of Microsoft’s Internet Explorer support SSL 3.0; that support needs to be disabled through the Options menu. And as for Apple’s Safari, the company’s security update 2014-005 mitigates the vulnerability while still allowing SSL 3.0.

Until you deactivate SSL 3.0, you might want to avoid connecting to public Wi-Fi networks. Otherwise sophisticated attackers occupying a privileged position on your network may be able to intercept your data, steal your passwords and browser cookies, and masquerade as you on websites, allowing them to hijack your accounts.

“In terms of security, when a protocol becomes deprecated that’s about the time you say we need to get off this and get off this soon,” says Waylon Grange, a senior malware researcher at Blue Coat, a Sunnyvale, Calif. cyber security firm. “It means a vulnerability or weakness has been found and people know it can be attacked.”

In the world of encryption, a newer, more secure protocol, Transport Layer Security (TLS) 1.0, replaced SSL 3.0 in 1999. Since then, there have been two updates—TLS 1.1 in 2006 and TLS 1.2 in 2008. Another, TLS 1.3, is in the works.

“This is almost four versions now,” Grange adds, “at some point you need to say, ‘Let’s move up.’”

How we got here

Some businesses may not wish to retire older protocols like SSL 3.0 since they want to ensure they can connect with every last potential customer. That means accommodating people who have not updated their browsers in eight years, when Internet Explorer 7 enabled TLS 1.0 support by default. “Do you really want those guys still on your networks?” Grange asks, noting that their machines are likely vulnerable to a host of other flaws—and adding that SSL 3.0 transactions represent less than one percent of all web traffic.

“If a machine is vulnerable with this, it’s likely to have other vulnerabilities because it’s that old,” Grange says. “It’s putting your whole network at risk because of this ancient technology.”

Then again, retaining older protocols like SSL 3.0 also provides a fallback option for browsers should connection attempts by newer protocols not work, for whatever reason—an if-all-else-fails approach. The problem is that savvy hackers can sit on a network, scramble communications, and frustrate a machine’s attempts to connect with a server, forcing it to fall back on an outdated protocol. The hackers perpetuating this type of attacks, referred to as man-in-the-middle, can then implement Poodle and steadily decrypt transacted sensitive information.

Hugh Thompson, chief security strategist at Blue Coat, says companies should retire SSL 3.0 as soon as possible, even if they’re unsure what old devices relying on it may still be connected to their networks. If a browser embedded in a printer has no update option, “it may just be time to get rid of that printer,” he says.

Forgotten, outdated devices are bound to have issues, he says. “Almost certainly something will stop working.” Nevertheless, “You should definitely deprecate it,” he says. “It’s definitely worth it.”

What to take away from the incident

Disabling SSL 3.0 is not the only lesson to be learned from Poodle. Consider the bigger picture: In the past year, three high-profile bugs have rocked the business world.

In April, the web was hit by Heartbleed, a frighteningly pervasive encryption vulnerability. Five months later we were shocked by Shellshock, a slightly less worrisome bug (because it poses more of a technical challenge to hackers) yet one that bore grave implications (like the ability of a hacker to take over machines). Now we have Poodle—and more bugs are bound to surface.

As Internet companies begin to encrypt more traffic across the web, attackers are going to become even more interested in finding cryptographic weaknesses. Businesses must learn to cope, Thompson says.

“If you thought Heartbleed was the equivalent of a meteorite hitting a data center,” Thompson says, “you would do everything you could to clean up from the meteorite. But you wouldn’t have set up some big meteorite cleaning processes. These three signal that this is not a rare event. If that’s the case, there is a need to be able to build up a set of competencies around failure.”

That means putting in place agile response teams, building network forensic capabilities and updating to new versions of software and protocols in a timely manner. It’s a matter of setting up the right processes and practicing good network hygiene, Thompson says. There is no excuse to be caught unaware–especially if, in the end, it appears your company is more concerned with backward compatibility than security.

Next, read: “How Home Depot CEO Frank Blake kept his legacy from being hacked” by Jennifer Reingold.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
Fortune Secondary Logo
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in

AIAnthropic
Anthropic CEO Dario Amodei says ‘we are patriotic Americans’ committed to defending the U.S. but won’t budge on ‘red lines’
By Jason MaFebruary 28, 2026
35 minutes ago
Middle EastIran
Iran is now on ‘death ground’ amid existential threat from U.S. attacks and could ‘go big’ in retaliation, former NATO commander warns
By Jason MaFebruary 28, 2026
2 hours ago
trump
LawTariffs
‘Why shouldn’t we get our money back too?’ Normal people are starting to demand Trump tariff refunds
By Mae Anderson and The Associated PressFebruary 28, 2026
3 hours ago
david ellison
Arts & EntertainmentHollywood
20 years ago, David Ellison’s flop as an actor stressed him out so much he went to the hospital. Now he’s set to own Paramount and Warner
By Matt Sedensky and The Associated PressFebruary 28, 2026
3 hours ago
warren
InvestingBerkshire Hathaway
Berkshire Hathaway shareholders just woke up to a letter by someone other than Warren Buffett
By Josh Funk and The Associated PressFebruary 28, 2026
3 hours ago
trump
PoliticsWhite House
Trump says Cuba has ‘no money’ and ‘maybe we’ll have a friendly takeover’
By Will Weissert and The Associated PressFebruary 28, 2026
3 hours ago

Most Popular

placeholder alt text
Success
Japanese companies are paying older workers to sit by a window and do nothing—while Western CEOs demand super-AI productivity just to keep your job
By Orianna Rosa RoyleFebruary 27, 2026
1 day ago
placeholder alt text
Success
Walmart exec says U.S. workforces needs to take inspiration from China where ‘5 year-olds are learning DeepSeek’
By Preston ForeFebruary 27, 2026
1 day ago
placeholder alt text
Personal Finance
Current price of gold as of February 27, 2026
By Danny BakstFebruary 27, 2026
1 day ago
placeholder alt text
Law
China's government intervenes to show Michigan scientists were carrying worms, not biological materials
By Ed White and The Associated PressFebruary 26, 2026
2 days ago
placeholder alt text
Commentary
'The Pitt': a masterclass display of DEI in action 
By Robert RabenFebruary 26, 2026
2 days ago
placeholder alt text
Economy
Come 2030, the U.S. deficit will be worth 5.9% of GDP—more than spending on Social Security, and equal to major health programs
By Eleanor PringleFebruary 26, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.