The FREAK Vulnerability

freak-ssl-tls-vulnerability

It’s recently come to our attention that another new SSL/TLS vulnerability has been uncovered named FREAK.

http://thehackernews.com/2015/03/freak-openssl-vulnerability.html

For over a decade, the vulnerability has left Millions of users of Apple and Android devices vulnerable to man-in-the-middle attacks on encrypted traffic when they visited supposedly ‘secured’ websites. The article states that “A scan of more than 14 million websites that support the SSL/TLS protocols found that more than 36% of them were vulnerable to the decryption attacks that support RSA export cipher suites.”

There is currently an Online SSL FREAK Testing Tool to check whether a website is vulnerable or not. Google and Apple have already reported a fix for the Vulnerability, and are requesting that all websites disable support for export certificates.