Windows is susceptible to 'FREAK' after all

Windows 8.1 is affected
Windows 8.1 is affected

Microsoft has confirmed that all Windows PCs are at risk from an HTTPS exploit known as FREAK that has already affected a raft of Android and Apple devices.

The bug was originally disclosed on Monday and it was thought that PCs running Windows weren't affected by the exploit that has existed for more than 10 years and allows attackers to easily decrypt traffic sent over an HTTPS connection between end users and websites.

Attacks can be carried out when an end-user on a vulnerable device connects to an HTTPS-protected site that is also vulnerable, and those sites that are at risk are ones that use the weak cipher that was thought to be long retired.

FREAK, which stands for factoring attack on RSA-EXPORT keys, allows those monitoring the traffic to introduce malicious packets into the traffic flow that force the end user and site to use a weaker 512-bit encryption key while in an encrypted web session.

Attackers can collect information transmitted over this exchange by using the cloud to factor the website's underlying private key. This process costs just $100 (around £66, or AU$130) and takes around seven hours to complete. Once that has taken place, the attacker can act as the official HTTPS-protected site to potentially read or modify data travelling between the site and end users.

No Windows patch

The scale of the problem was laid bare by a report by security researchers on FREAKattack.com that found 36% of the 14 million HTTPS-protected sites it surveyed were using the weak cipher.

Apple and Google have already released updates that get around the problem and, although Microsoft has yet to develop a patch to bypass the problem that affects all consumer versions of Windows, it is advising users to apply a workaround that is detailed here.

Via: Ars Technica

Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
A young woman is working on a laptop in a relaxed office space.
I’ll admit, Microsoft’s new Windows 11 update surprised me with its usefulness, providing accessibility fixes, a gamepad keyboard layout, and PC spec cards
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Nespresso Vertuo Pop machine in Candy Pink with coffee drinks and capsules
My favorite Nespresso coffee maker just got a fresh new makeover, and now I love it even more
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC