Jump to content

Windows Vulnerabe to Freaking After All


ebrke

Recommended Posts

It isn't only browsers/OSes that are vulnerable but websites as well. From what I've read, Gregg Keiser describes it best in Time to FREAK out? How to tell if you're vulnerable:

 

FREAKin' vulnerability. A vulnerable server does not necessarily mean that traffic between your browser and the website can be sniffed.

 

Both the browser and the server must support the export-grade cipher suites in order for an attack to be successful. "You are vulnerable if you use a Web browser that uses a buggy TLS library to connect, over an insecure network, to an HTTPS server that offers export cipher suites," the researchers wrote in a summary of their findings.

 

So even if you're connecting to sec.gov, the website of the U.S. Securities and Exchange Commission, and one of the sites that supports export cipher libraries (as of early Wednesday), you're safe if you're using, say, Chrome on OS X, because the latter does not support export suites. Only if both ends are insecure -- such as a Safari-to-sec.gov connection -- are you vulnerable.

  • Like 1
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...