New FREAK Attack Threatens Many SSL Clients

JMH

Emeritus, Contributor
Joined
Apr 2, 2012
Posts
7,197
For the nth time in the last couple of years, security experts are warning about a new Internet-scale vulnerability, this time in some popular SSL clients. The flaw allows an attacker to force clients to downgrade to weakened ciphers and break their supposedly encrypted communications through a man-in-the-middle attack.

Researchers recently discovered that some SSL clients, including OpenSSL, will accept weak RSA keys–known as export-grade keys–without asking for those keys. Export-grade refers to 512-bit RSA keys, the key strength that was approved by the United States government for export overseas. This was an artifact from decades ago and it was thought that most servers and clients had long ago abandoned such weak ciphers.
New FREAK Attack Threatens Many SSL Clients | Threatpost | The first stop for security news
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top