Tuesday, March 3, 2015

FYI: Tracking the FREAK Attack

"On Tuesday, March 3, 2015, researchers announced a new SSL/TLS vulnerability called the FREAK attack. It allows an attacker to intercept HTTPS connections between vulnerable clients and servers and force them to use weakened encryption, which the attacker can break to steal or manipulate sensitive data. This site is dedicated to tracking the impact of the attack and helping users test whether they’re vulnerable.
The FREAK attack was originally discovered by Karthikeyan Bhargavan at INRIA in Paris and the mitLS team. Further disclosure was coordinated by Matthew Green. This report is maintained by computer scientists at the University of Michigan, including Zakir DurumericDavid Adrian, Ariana Mirian, Michael Bailey, and J. Alex Halderman. The team can be contacted at freakattack@umich.edu.
For additional details about the attack and its implications, see this post by Matt Greenthis Washington Post article, and this post by Ed Felten." 
Continue Reading at https://freakattack.com

No comments: