Skip to main content

Microsoft now says Windows computers could have a ‘FREAK’ attack

kentucky hospital subjected to ransomware hacker keyboard
Computers running Windows are vulnerable to the so-called “FREAK” attack, which gives hackers the power to decrypt secure traffic between a web surfer’s browser and the site she is visiting. Microsoft had said at first that the Windows system was immune to such attacks, but a recent advisory posted to the company’s TechNet site has confirmed the vulnerability.

“Microsoft is aware of a security feature bypass vulnerability in Secure Channel that affects all supported releases of Microsoft Windows,” the company wrote. “We are actively working with partners in our Microsoft Active Protections Program to provide information that they can use to provide broader protections to customers.”

Until the situation is under control, users are vulnerable to FREAK — but what is it exactly?

“FREAK” is short for Factoring attack on RSA-EXPORT Keys, according to ArsTechnica.com. The attacks are possible when a vulnerable user logs onto a vulnerable HTTPS-protected website using a device prone to being compromised. In this case, Windows computers fall into that category.

PCs and laptops aren’t the only products that could have a FREAK attack, however. Prior to the announcement from Microsoft, everything from iPhones to Android devices was thought to be susceptible to an attack.

During a FREAK attack, hackers watch the traffic passing between browsers and vulnerable servers. They can then inject malicious packets into the flow that cause the two parties to use a weak, 512-bit encryption key. With this weakness in place, hackers can collect some of the exchanged information using cloud-based computing.

Security researchers have found that out of 14 million HTTPS-protected websites, about 36 percent of them supported weak cipher, rendering them vulnerable to a FREAK attack. They note that companies including Google, Microsoft, and Apple have been slow to develop patches, which hints that FREAK attacks pose a low threat at the moment.

So don’t FREAK out just yet.

Editors' Recommendations

Krystle Vermes
Former Digital Trends Contributor
Krystle Vermes is a professional writer, blogger and podcaster with a background in both online and print journalism. Her…
It’s not just you: Microsoft confirms Windows 11 is having gaming issues
Acer Predator Orion 7000 sitting on a table.

Microsoft has confirmed that the latest update to Windows 11 is causing performance issues in some games, along with a host of other problems. Stuttering might be noticeable in some apps as well.

Microsoft has put a hold on its Windows 11 22H2 update on devices affected by this issue; however, it is still possible to install the update manually. If you haven’t updated yet, it’s best to wait until you get a notification that an update is available.

Read more
Update Windows now — Microsoft just fixed several dangerous exploits
Person sitting and using an HP computer with Windows 11.

Microsoft has just released a new patch, and this time around, the update comes with fixes for several dangerous and actively abused vulnerabilities and exploits in Windows.

A total of 68 vulnerabilities were addressed in the patch, many of them critical. Here's what was fixed and how to make sure your Windows device is up to date.

Read more
Microsoft just teased its next big Windows 11 update
Windows 11 22H2 Tablet Taskbar YouTube screenshot

Microsoft has given us a glimpse of a feature that "Moment 2" may bring as early as January 2023.

Since Windows 11 version 22H2, the Redmond, WA company has dedicated to releasing smaller feature updates, known internally as "Moment." The first one gave us the much-requested tabs in File Explorer (along with its Context IQ tech). The next Windows 11 version 22H2 "Moment" is currently slated for early 2023, according to sources, after it undergoes testing throughout 2022.

Read more