Forum Moderators: phranque

Message Too Old, No Replies

"Freak" Security Flaw Could Impact Apple and Google Users

         

engine

12:17 pm on Mar 4, 2015 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



How is it that these flaws are only now being discovered in such a way. Perhaps there have been few, or no man-in-the-middle attacks!

The Apple patch sounds as if it's on its way, but the delivery of the Google patch is a little concerning.


Researchers discovered in recent weeks that they could force browsers to use the weaker encryption, then crack it over the course of just a few hours. Once cracked, hackers could steal passwords and other personal information and potentially launch a broader attack on the Web sites themselves by taking over elements on a page, such as a Facebook “Like” button."Freak" Security Flaw Could Impact Apple and Google Users [washingtonpost.com]
More than one third of encrypted Web sites – including those bearing the “lock” icon that signifies a connection secured by SSL technology – proved vulnerable to attack in recent tests conducted by University of Michigan computer science researchers J. Alex Halderman and Zakir Durumeric.
Apple is preparing a security patch that will be in place next week for both its computers and its mobile devices, said company spokeswoman Trudy Miller.

Google’s Chrome browser is not vulnerable to the FREAK bug, but the browser that comes built into most Android devices is vulnerable. Connections to Google’s search Web site are not affected by the flaw.

bill

6:34 am on Mar 11, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Microsoft's Patch Tuesday this week addresses the issue as well. MS15-031 specifically patches the security feature bypass vulnerability in Schannel, the Windows implementation of SSL/TLS, that enables FREAK attacks.

Microsoft Security Bulletin MS15-031 - Important
Vulnerability in Schannel Could Allow Security Feature Bypass (3046049)
[technet.microsoft.com...]

engine

10:08 am on Mar 11, 2015 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



31 updates on my machine this morning: That must be close to a record.