Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

FREAK OpenSSL Bug: What Apple Users Need to Know
Intego.com ^ | March 3rd, 2015 | by Derek Erwin

Posted on 03/04/2015 11:38:13 AM PST by Swordmaker

Security researchers have discovered a crippling OpenSSL bug in Apple and Google devices, as well as many high profile websites, which could allow “man in the middle” attacks. These attacks can occur when Apple users are on public Wi-Fi networks, where they can be fooled into connecting to rogue servers claiming to belong to someone else.

The “FREAK” vulnerability (CVE-2015-0204), short for Factoring attack on RSA-EXPORT Keys, makes it possible for attackers to decrypt and monitor HTTPS-protected traffic.

A FREAK attack is possible when someone with a vulnerable device—Mac OS X computers, iOS and Android devices—connects to an HTTPS-protected website configured to use an easily breakable key once thought to be dead. It requires that the attacker be in a position where they can intercept packets between the endpoint device and the HTTPS-protected website.

How did we get here?

The flaw resulted from a former policy of the Clinton administration, which required weak 512-bit keys to be used in any software or hardware that was exported out of the United States. The U.S. government forbade the export of strong encryption in products shipped to customers in other countries.

These restrictions were lifted in the late 1990s, but somehow the weaker encryption have managed to remain in widely used software and hardware around the world, including the United States, and went unnoticed by the public until recently.

How to tell if a website is vulnerable

If you have a Mac OS X system, open Terminal and run this line of code:

openssl s_client -connect www.akamai.com:443 -cipher EXPORT

If it returns "alert handshake failure" in its answer, then the host site is safe.

To check if another site is safe, substitute "www.akamai.com" with another hostname.

How to tell if your browser is vulnerable

Type this web address directly into your browser address bar:

https://freakattack.com

On this page, you can see if your browser is vulnerable, and it has a list of every vulnerable website. At the time of writing this post, only Firefox is safe to use on Mac OS X (both Safari and Google Chrome are vulnerable).

Have hackers figured out how to exploit the FREAK flaw?

There is no published attack using this vulnerability, but that doesn’t mean it's not happening. Given the age of this vulnerability, someone has probably figured out how to exploit it, at least by the NSA. However, successful exploitation is not exactly easy to accomplish without physical access to the hotspot hardware.

This means that attacks can be launched by anyone who has access to Internet traffic, which includes governments, Internet Service Providers (ISPs), coffee shops or airports, and any other locations offering Wi-Fi hotspots. A malicious hotspot owner could exploit the vulnerability, or someone spoofing the Starbucks hotspot from a nearby location. And a well-versed hacker could pull it off, but it’s really not that simple.

Dan Goodin at Ars Technica described what can happen, and said:

[A]ttackers on a coffee-shop hotspot or other unsecured network can masquerade as the official website, a coup that allows them to read or even modify data as it passes between the site and the end user.

How can the FREAK vulnerability be resolved?

Apple can patch this on the client side, and they no doubt will soon. Web server hosts can also patch this on the server side, which they no doubt are doing as well.

Intego is continuing to research this threat and will continue to provide updates as new information becomes available.

What can you do to stay protected?

To stay safe on Macs, use Firefox.

On iOS devices, avoid using any public Internet access options (i.e. sitting in Starbucks or using free airport Wi-Fi) and doing things like banking and email. If you must use a public Wi-Fi hotspot, use a VPN (see Cloak as a paid option, or Onavo Protect as a free option), don't send personal or private information if you can avoid it, and never accept any software updates.


TOPICS: Business/Economy; Computers/Internet
KEYWORDS:

1 posted on 03/04/2015 11:38:13 AM PST by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; altair; ...
Information on FREAK vulnerability for Apple and Android users. Affects Google Chrome users as well. There are no known exploits in the wild. . . but Intego speculates there may be unknown exploits, but such exploits would have to be Man-in-the-Middle-Attacks, implemented at locations where you'd use a public WIFI. — PING!


Apple, Android, and Google Chrome Security Ping!

If you want on or off the Mac Ping List, Freepmail me.

2 posted on 03/04/2015 11:42:15 AM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Buy a pc.

(Couldn’t resist!)


3 posted on 03/04/2015 11:47:14 AM PST by Boogieman
[ Post Reply | Private Reply | To 1 | View Replies]

To: Boogieman

Hey, take your proselytizing to the Religion threads ............


4 posted on 03/04/2015 11:52:19 AM PST by mikrofon (Humpday BUMPty)
[ Post Reply | Private Reply | To 3 | View Replies]

To: mikrofon

Sure, when Appleheads stop posting their “get a mac” comments on any thread someone posts about a pc issue, I will.


5 posted on 03/04/2015 11:56:44 AM PST by Boogieman
[ Post Reply | Private Reply | To 4 | View Replies]

To: Boogieman
Yep get a PC….💩 Owned a MAC 👍 since early 90's and would NEVER own a PC 🚽 except in VM or Parallels Desktop. The only way to fly. 🚀 Thanks for the information Swordmaker.
6 posted on 03/04/2015 12:14:43 PM PST by Johnny_cash
[ Post Reply | Private Reply | To 5 | View Replies]

Less Than 1K To Go!


Click The Pic To Donate

Please Donate!

7 posted on 03/04/2015 12:21:48 PM PST by DJ MacWoW (The Fed Gov is not one ring to rule them all)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

bfl


8 posted on 03/04/2015 12:22:00 PM PST by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Its bigger than this Swordmaker. Based on NIST recommendations the PCI Council has decided SSL is no longer considered strong encryption. V1 & V2 have long been considered outdated. SSL V3 has been added to the list.


9 posted on 03/04/2015 12:28:45 PM PST by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Safari Version 8.0.5 (10600.5.6)

10 posted on 03/04/2015 2:14:02 PM PST by TheBattman (Isn't the lesser evil... still evil?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Chrome Version 41.0.2272.76 (64-bit)

Both under OS X Yosemite 10.10.3

11 posted on 03/04/2015 2:17:46 PM PST by TheBattman (Isn't the lesser evil... still evil?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

so, for now, avoid public hot spots for banking and credit card transactions. I can deal.


12 posted on 03/04/2015 6:04:37 PM PST by conservatism_IS_compassion ('Liberalism' is a conspiracy against the public by wire-service journalism.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: conservatism_IS_compassion

Are you getting any Apple thread pings? I have emailed you and several others on the ping list and I am getting no responses. . . and my Pings are not getting the normal level of responses.


13 posted on 03/04/2015 7:42:44 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Swordmaker

Cloak and Onavo Protect VPNs. Never heard of these. Thoughts?


14 posted on 03/04/2015 9:11:58 PM PST by ProtectOurFreedom (For those who understand, no explanation is needed. For those who do not, no explanation is possible)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ProtectOurFreedom
Cloak and Onavo Protect VPNs. Never heard of these. Thoughts?

They are virtual private networking software for iPhones and iPads available on the Apple App Store. Cloak is no longer exactly free, because after a 30 day free trial, you have to do an in-App purchase to continue using it. Onavo Protect is free. Both are modern VPNs that use the latest security tech.

15 posted on 03/04/2015 10:08:13 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 14 | View Replies]

To: Swordmaker

Bump.


16 posted on 03/05/2015 11:37:25 AM PST by conservatism_IS_compassion ('Liberalism' is a conspiracy against the public by wire-service journalism.)
[ Post Reply | Private Reply | To 13 | View Replies]

To: driftdiver

I keep getting annoying calls about being in PCI compliance at my business.

We recently dumped our credit card processing company and moved everything over to Square. Do we still have to worry about PCI compliance? The whole thing sounds like a scam.


17 posted on 03/05/2015 11:43:36 AM PST by Crusher138 ("Then conquer we must, for our cause it is just")
[ Post Reply | Private Reply | To 9 | View Replies]

To: Crusher138

If you accept credit cards for payment you are contractually bound to being PCI compliant.

As a general rule if you do less than 400,000 transactions a year the card brands wont pay a lot of attention. If you use a certified vendor like Square to do it you are pretty much there. Just don’t keep any paper records of the card number in addition to using that service.

There are concerns about Square for compliance but they are one of the approved ones the last time I checked.

Yes its a scam, a legal one. The banks don’t really care because credit card fraud costs them less than 5 cents on every $100 spent. For them that is acceptable.


18 posted on 03/05/2015 12:16:34 PM PST by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 17 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson