Skip to main content

Worried about a FREAK? The latest Windows patch may put you at ease

Windows 7 desktop.
Mr.Follow/Windows Wikia
After confirming that all Windows computers are vulnerable to a FREAK attack, Microsoft released a patch on March 10 that protects machines against data interception. The announcement was made on the company’s TechNet blog.

“This security update resolves a vulnerability in Microsoft Windows that facilitates exploitation of the publicly disclosed FREAK technique, an industry-wide issue that is not specific to Windows operating systems,” the post stated.

Related: Microsoft now says Windows computers could have a ‘FREAK’ attack

The MS15-031 update, as it’s been named, is being recommended to Windows users for installation. Microsoft has fixed SSL implementations in its software to reduce the chances of a FREAK attack.

FREAK is short for Factoring attack on RSA-EXPORT Keys. When a FREAK attack occurs, hackers have the ability to intercept information that is transferred between an end-user and a website. The attacker begins by injecting malware into the connection that causes the two parties to use a weak, 512-bit encryption key. After this has happened, the weak connection allows the hacker to tap into sensitive data.

Microsoft had originally said that Windows was not vulnerable to an attack, but quickly backtracked with an announcement on its TechNet blog last week.

“Microsoft is aware of a security feature bypass vulnerability in Secure Channel that affects all supported releases of Microsoft Windows,” the company wrote. “We are actively working with partners in our Microsoft Active Protections Program to provide information that they can use to provide broader protections to customers.”

Smartphones and devices that run iOS or Android have been deemed susceptible to FREAK attacks, so Windows users aren’t the only ones with something to worry about.

Editors' Recommendations

Krystle Vermes
Former Digital Trends Contributor
Krystle Vermes is a professional writer, blogger and podcaster with a background in both online and print journalism. Her…
Microsoft plans to charge for Windows 10 updates in the future
Windows 11 and Windows 10 operating system logos are displayed on laptop screens.

Microsoft has confirmed it will offer security updates for Windows 10 after the end-of-life date for the operating system for consumer users but for a fee.

The brand recently announced plans to charge regular users for Extended Security Updates (ESU) who intend to continue using Windows 10 beyond the October 14, 2025 support date.

Read more
Windows may have a serious security problem on its hands
A finger pressing on a fingerprint reader on a laptop.

The premier sensors enabling Windows Hello fingerprint authentication are not as secure as manufacturers had hoped. Researchers have discovered security flaws in a number of fingerprint sensors used in several laptops that work with the Windows Hello authentication feature.

Security researchers at Blackwing Intelligence have uncovered that laptops made by Dell, Lenovo, and Microsoft can have their Windows Hello fingerprint authentication bypassed easily due to vulnerabilities in the sensors that can cause them to be taken over by bad actors at the system level.

Read more
This simple keyboard shortcut could save you when installing Windows 11
The Command Prompt on screen during Windows 11 installation.

I install Windows 11 a lot. Be it for a clean slate on a PC that's acting up or a brand new PC, anyone who tinkers with computers will find themselves interacting with the Windows installer quite a bit. And it's far from perfect.

Over the past year, it's gotten worse, too. This is because Windows 11 now requires you to connect to the internet before proceeding with installation. If you don't have a connection (or another issues occurs, as I'll get to in a moment), you're out of luck. You're stuck. Thankfully, there's a Windows 11 shortcut that can crack open the installer and give you a lot more power: Shift + F10. 

Read more