ATTENTION: You are viewing a page formatted for mobile devices; to view the full web page, click HERE.

Main Area and Open Discussion > General Software Discussion

Microsoft reveals Windows vulnerable to FREAK SSL flaw

(1/1)

Renegade:
Another security issue.

http://www.zdnet.com/article/microsoft-reveals-windows-vulnerable-to-freak-ssl-flaw/

The FREAK security bug that allows attackers to conduct man-in-the-middle attacks on Secure Sockets Layer (SSL) and Transport Layer Security (TLS) connections encrypted using an outmoded cipher has claimed another victim. This time, it is Microsoft's Secure Channel stack.

"Microsoft is aware of a security feature bypass vulnerability in Secure Channel (Schannel) that affects all supported releases of Microsoft Windows," the company said in a security advisory. "The vulnerability facilitates exploitation of the publicly disclosed FREAK technique, which is an industry-wide issue that is not specific to Windows operating systems."

Although Microsoft Research was part of the team to uncover FREAK alongside European cryptographers, Redmond chose not to reveal Windows as vulnerable until today.
--- End quote ---

More at the link.

Stoic Joker:
In other news, it appears that if one was staying up-to-date on any of the other myriad of SSL flaws over the past several years, then you're safe from this on too...when using IE.

This is the same bugg I mentioned in passing here. I did the testing on it then, and all systems passed. I just did the testing at the ZDNet links...and all systems still passed (with IE11).

Since this thing was apparently gestated back in the 90s, shouldn't they be calling it the asleep-at-the-wheel bugg..?

Renegade:
In other news, it appears that if one was staying up-to-date on any of the other myriad of SSL flaws over the past several years, then you're safe from this on too...when using IE.
-Stoic Joker (March 07, 2015, 06:26 AM)
--- End quote ---

Well, that's some good news.

Navigation

[0] Message Index

Go to full version