Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

No evidence of FREAK exploits and no patches should not cause complacency

by The Gurus
March 4, 2015
in Editor's News
Share on FacebookShare on Twitter

The delay in patching the FREAK flaw will not cause users problems, particularly as there is currently no evidence of any exploits.
 
In an email to IT Security Guru, TK Keanini, CTO of Lancope said that proper exploitation of this flaw is difficult because there are multiple requirements for the attacker, unlike other vulnerabilities where all they needed to do was run the exploit.
 
“For this reason, I don’t think the delay [in releasing a patch] is a bad thing because a fix and proper testing of that fix is  important as we don’t want o be introducing even more vulnerabilities,” he said.
 
Mark James, security specialist at ESET, said that once a flaw has been made public, any delay will increase the chances of it being exploited. “Whilst a small number of people may be aware of this flaw already, once it goes public any number of people may then attempt to use this for the wrong reasons,” he said.
 
“It certainly is good news that there is currently no evidence of any exploits, however evidence and practice do not necessarily go hand in hand. Getting this patched as soon as possible by all the affected software parties is a priority and it’s good to see that some already have.”
 
Revealed yesterday, the FREAK (Factoring attack on RSA-EXPORT Keys) flaw allows interception of vulnerable clients and servers and forces them to use ‘export-grade’ cryptography, which can then be decrypted. The technique could be used to decrypt users name and passwords as well as other sensitive that users may think is protected by SSL. According to NCC Group, there is currently no evidence that attackers have managed to exploit the weaknesses yet. According to Reuters, Apple has said a software update will be pushed out next week, while Google said the company had also developed a patch, which it has provided to partners.
 
Keanini said: “Only the most sophisticated and advanced would be able to pull this off and those are the types of attackers that only make the news when they choose to make the news. Very few attackers have at the ready the ability to get in the middle of your network traffic.
 
“This does not mean that the vulnerability cannot be exploited, it just means it will be much more targeted and only a small handful of attackers will have the opportunity at this point.”
 
Gavin Millard, EMEA technical director of Tenable Network Security, told IT Security Guru that he felt that FREAK was far less of an issue than Heartbleed and similar to POODLE, but it was still worth taking note and fixing the issues where present.
 
He said: “With all major bugs of this type, it is important that the affected systems are identified and updated when the patches are available to reduce the risk of this vulnerability being exploited. OpenSSL has a patch available now, the client updates should follow in the coming days.”
 
Phil Lieberman, CEO of Lieberman Software Corporation agreed that FREAK is a low probability threat, so little needs to be done, but recommended websites or embedded systems which may be compromised by nation states using this technique, they will need to upgrade their web servers to use a more modern version of OpenSSL
 
He called Heartbleed was a serious and prevalent flaw that affected most users interacting with open source based web servers, and a “you must patch” scenario for internet-facing sites. “FREAK is an interesting technique, but it should not keep anybody awake at night unless their Internet connection is tapped or are using WiFi without encryption and authentication,” he said.

Tags: EncryptionFlawFREAKHeartbleedHTTPS
ShareTweet
Previous Post

National Security Strategy report highlights steady evidence of need for cyber spending

Next Post

More than 700 cloud services are vulnerable to FREAK flaw

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol