Another Major Security Flaw (Website Encryption Technology) Called Logjam

The group of researchers created a website to explain their findings: The Logjam Attack (

It looks like they also did a scan of the Internet (this is typical of security researchers using and found over 8.4% of Top1 million domains were at risk. This means 84,000 websites are at risk.

There are more websites that could be at risk if the 1024 bit group is broken 17.9% of top1 million domains. (179,000).

I suspect there are many more websites vulnerable to this potential attack, I believe that the hackers are busy right now trying to use this new attack method to attack specific websites that there was no way to attack before.

The researchers have developed a test to test your own server:


In this link there are 3 Steps to accomplish a fix on your site (deploying Diffie-Hellman for TLS)

1. disable Export Cipher Suites

2. Deploy (Ephemeral) elliptic-Curve Diffie-hellman(ECDHE)

3. Generate a Strong, Unique Diffie Hellman Group (at least 2048bit or stronger. using a safe prime.



So to summarize:

If you have a https (encrypted website) on your webserver please review the details of your cryptographic Cipher technique. If needed please change to 2048bit or higher Diffie-Hellman Group.

logjam-whoisaffected(from the website)

Here is a wiki on  that describes the different methods of Diffie-Hellman (which has to do with generating the key for the cryptographic exchange between the 2 systems)

Ephemeral Diffie-Hellman uses temporary, public keys. Each instance or run of the protocol uses a different public key. The authenticity of the server’s temporary key can be verified by checking the signature on the key. Because the public keys are temporary, a compromise of the server’s long term signing key does not jeopardize the privacy of past sessions. This is known as Perfect Forward Secrecy (PFS).


If you are interested in these kinds of details there are many sites to educate on this topic including this one: by Richard Schwartz.



If you need help in deciding if your website is susceptible to this attack concept please contact us

