DATA DOCTORS

Security alert for smartphone and Mac users

Mar 6, 2015, 9:51 PM | Updated: Apr 24, 2015, 8:13 pm

Q: What exactly is the FREAK security flaw that’s been discovered on smartphones and what do I need to do about it?

A team of security researchers and cryptographers have discovered a security flaw that dates back to the early days of the Internet and exists in many popular browsers.

Users of Safari on Mac and iOS devices, as well as stock browsers on many Android devices, are potentially vulnerable to being exploited when they visit certain secure websites (https://).

It’s being called FREAK or “Factoring Attack on RSA-EXPORT Key” and it’s the remnants of the U.S. government’s restriction on the export of strong encryption back the 1990’s.

This forced developers to devise a system that could deliver strong encryption for U.S.-based users and the weaker encryption for foreign users. It was all in an attempt to allow the government to better monitor the Internet activity of foreign users by not allowing them to use our more powerful encryption.

The requirement was later dropped, but by that time, this dual encryption delivery system had become a standard part of web browsers.

Today, this legacy design still exists in some popular programs, which leaves users of these programs vulnerable to some pretty serious exploitation on sites that they may assume are secure.

We’ve all been told to look for https:// sites to know that the connection between us and the website is secure, but the researchers found a way to exploit this legacy issue. They discovered that they could force browsers to use the older, weaker encryption, then crack it over the course of a couple hours.

Once they broke the encryption, they could steal passwords and personal information and even take over websites themselves to further their attacks.

Researchers have been scanning websites around the Internet to see how many may be using this exploitable hole. They found 10 percent of the top one million most popular secure sites and almost 40 percent of sites that your browser would trust are vulnerable.

The good news, so far, is that they’ve haven’t seen evidence of any exploits in the wild. The bad news is it’s just a matter of time.

If you have a Mac computer, iPhone, iPad or iPod Touch and you still use the Safari browser or you’re using the default browser on many Android devices, you’re the most vulnerable.

Users of current versions of Internet Explorer, Chrome or Firefox are not at risk.

I’ve always recommended the use of either Chrome or Firefox for any computer or mobile device, because I like some of the unique security features built in. If you’re a Mac, iOS or Android user, I’d strongly recommend you switch permanently.

To reduce the confusion on which devices you own that might be at risk, take a minute to visit FreakAttack.com on everything you own.

The website will test your browser and let you know if what you are using is potentially vulnerable. If you’re using an older version of Internet Explorer, Chrome or Firefox, you may need to update it in order to protect yourself.

Apple and Google are reportedly working on fixes, so in the next week or so, you need to make sure and download the updates when they are posted.

If you’re a webmaster, FreakAttack.com has posted recommendations for what you should do to disable the exploit on your webserver.

Data Doctors

Patrick Mahomes #15 and head coach Andy Reid of the Kansas City Chiefs are recorded on a phone as t...

Data Doctors

Handy tech tips all Valley residents should use to find lost phones in a snap

Q: My phone went missing, and I haven’t been able to locate it using the Find My service, so what should I do next?

6 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are tips for freeing up Google storage space

Google provides a generous amount of free online storage but it can fill up quickly depending on how many of its resources you use.

13 days ago

Discover how to assess, estimate, and shop for the right battery pack with this concise guide. (Pex...

Data Doctors

Here is everything you need to know for testing and buying battery banks

Discover how to assess, estimate and shop for the right battery pack with this concise guide.

20 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are the truly free smartphone video editing apps

The processing power on our smartphones has grown exponentially, allowing anyone to perform sophisticated video editing easily.

27 days ago

Google Maps app....

Data Doctors

How to rediscover places visited years ago on Google maps

Whether you're an Android or iOS user, or prefer accessing Google Maps on your computer, you'll find step-by-step instructions to unlock your travel memories effortlessly.

1 month ago

(Photo by Michael Bocchieri/Getty Images)...

Ken Colburn, Data Doctors

Here’s how to calculate your bandwidth needs

When searching for an alternative internet service provider, here are some tips on how to know how much bandwidth is needed.

1 month ago

Sponsored Articles

...

Condor Airlines

Condor Airlines can get you smoothly from Phoenix to Frankfurt on new A330-900neo airplane

Adventure Awaits! And there's no better way to experience the vacation of your dreams than traveling with Condor Airlines.

...

Day & Night Air Conditioning, Heating and Plumbing

Day & Night is looking for the oldest AC in the Valley

Does your air conditioner make weird noises or a burning smell when it starts? If so, you may be due for an AC unit replacement.

...

Collins Comfort Masters

Avoid a potential emergency and get your home’s heating and furnace safety checked

With the weather getting colder throughout the Valley, the best time to make sure your heating is all up to date is now. 

Security alert for smartphone and Mac users