Skip to main content

Microsoft now says Windows computers could have a ‘FREAK’ attack

kentucky hospital subjected to ransomware hacker keyboard
Image used with permission by copyright holder
Computers running Windows are vulnerable to the so-called “FREAK” attack, which gives hackers the power to decrypt secure traffic between a web surfer’s browser and the site she is visiting. Microsoft had said at first that the Windows system was immune to such attacks, but a recent advisory posted to the company’s TechNet site has confirmed the vulnerability.

“Microsoft is aware of a security feature bypass vulnerability in Secure Channel that affects all supported releases of Microsoft Windows,” the company wrote. “We are actively working with partners in our Microsoft Active Protections Program to provide information that they can use to provide broader protections to customers.”

Until the situation is under control, users are vulnerable to FREAK — but what is it exactly?

“FREAK” is short for Factoring attack on RSA-EXPORT Keys, according to ArsTechnica.com. The attacks are possible when a vulnerable user logs onto a vulnerable HTTPS-protected website using a device prone to being compromised. In this case, Windows computers fall into that category.

PCs and laptops aren’t the only products that could have a FREAK attack, however. Prior to the announcement from Microsoft, everything from iPhones to Android devices was thought to be susceptible to an attack.

During a FREAK attack, hackers watch the traffic passing between browsers and vulnerable servers. They can then inject malicious packets into the flow that cause the two parties to use a weak, 512-bit encryption key. With this weakness in place, hackers can collect some of the exchanged information using cloud-based computing.

Security researchers have found that out of 14 million HTTPS-protected websites, about 36 percent of them supported weak cipher, rendering them vulnerable to a FREAK attack. They note that companies including Google, Microsoft, and Apple have been slow to develop patches, which hints that FREAK attacks pose a low threat at the moment.

So don’t FREAK out just yet.

Editors' Recommendations

Krystle Vermes
Former Digital Trends Contributor
Krystle Vermes is a professional writer, blogger and podcaster with a background in both online and print journalism. Her…
Windows is just an application now
Welcome screen of the Windows App on MacOS.

In a move toward enhancing remote desktop experiences, Microsoft has unveiled a new application at the ongoing Ignite developer conference. Aptly named the "Windows App," this tool serves as a remote utility, providing users with a centralized platform to manage various remote desktop connections. Whether you're utilizing Azure Virtual Desktop, Microsoft Dev Boxes, or traditional Remote Desktop connections, it can streamline the control of these connections in one accessible location.

Having an intuitive interface, it features distinct sections like a home page, device page, and app page. Remote sessions are organized in large windows, displaying essential details such as wallpaper, host system name, and system specifications (available on Windows 365 machines). It also supports custom display resolutions with support for scaling, as well as device redirection for peripherals like webcams, storage, and printers.

Read more
If you have an AMD GPU, stay away from the latest Windows Update
Two AMD Radeon RX 7000 graphics cards on a pink surface.

A quick PSA: If you own one of AMD's best graphics cards and you like to tweak the settings, now is not a good time to download the latest Windows Update. According to users on the AMD forums, the KB5030310 update really doesn't agree with AMD's Adrenalin Control Panel. While it's not the end of the world, this isn't the first Windows update in the last few months that has caused problems.

It appears that every time people restart their PCs, their Adrenalin settings are all reset back to default. This means that any changes made to things like AMD's Anti-Lag or Hyper RX will disappear upon every boot. Fortunately, the graphics driver itself is unaffected.

Read more
I hope Microsoft adds this rumored AI feature to Windows 11
A Windows 11 device sits on a table.

From smart speakers to ChatGPT and Bing Chat, AI has slowly crept into our lives, but not all instances of AI are as prominent as those three examples. Sometimes, the effect is subtle, but still pretty nice. It appears that Microsoft is working on one such instance of AI-enhanced tech that could make using Windows 11 just a little more pleasant. We're talking about AI-powered live wallpapers, and they might be coming soon.

First spotted by Windows Latest, Microsoft is readying an AI-powered desktop that could make the whole user experience feel a lot more interactive. The idea is to adjust depth perception and make some backgrounds appear more "alive" when moving your cursor or the entire device. The wallpaper might move or shift, depending on what you're doing on the desktop.

Read more