Security flaw from the ‘90s is still a problem today

Security flaw from the '90s is still a problem today

The flaw leaves Apple and Android users vulnerable

According to reports, a security flaw from the ‘90s has recently been discovered that leaves users vulnerable to cyberattacks today. A team of cryptographers has named the weakness “Factoring attack on RSA-EXPORT Key” or FREAK for short. It leaves everyone who uses Safari on Mac and iOS devices as well as Android’s stock browser vulnerable to hacking when they visit secure websites, such as those of the U.S. government.

This stems from a decision made in the ‘90s when the government required weaker encryption on websites for those who were attempting to access them from outside the U.S., thus allowing the NSA to access those communications more easily.

Eventually the government got rid of this requirement, but the encryption was already built from the ground-up into many different software applications which are still used today.

Researchers from Johns Hopkins have proved that this weakness can be used to steal a visitor’s personal information, as well as hack into the website itself. They can’t say whether anyone has already exploited the flaw, but Apple and Google are currently working on a patch regardless.

About the Author

Matt Holden is an Associate Content Editor for 1105 Media, Inc. He received his MFA and BA in journalism from Ball State University in Muncie, Indiana. He currently writes and edits for Occupational Health & Safety magazine, and Security Today.

Featured

New Products

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.