PC Users Left Vulnerable by Security Flaw

| March 9, 2015 in National News

Local Community Advertising

PC users are left vulnerable when visiting secure websites after a security flaw referred to as “FREAK” was confirmed by Microsoft on Thursday.

In a press release, Microsoft acknowledge a security feature bypass vulnerability in Secure Channel (Schannel) that affects all supported Microsoft Windows.

Schannel refers to the Security Support Provider that implements the Secure Sockets Layer (SSL) and Transport Layer Security(TLS). These components are used to facilitate secure communications while surfing the net and network applications.

Essentially, the security flaw can allow an attacker to spy on users via downgrading of the cipher suites used in the SSL and TLS components. 

When the security issue came to light, Microsoft initially believed PC users would not be affected by the vulnerability, however; the company has since confirmed FREAK exploitation.

The vulnerability facilitates exploitation of the publicly disclosed FREAK technique, which is an industry-wide issue that is not specific to Windows operating systems. When this security advisory was originally released, Microsoft had not received any information to indicate that this issue had been publicly used to attack customers,” read the press release.

In the event of security vulnerability, Microsoft suggests that PC users apply workarounds. Workarounds are a setting or configuration change that won't correct the underlying isssue, but will help block known attack vectors before a security update is available.

To apply workarounds users can disable the RSA key exchange ciphers in Windows Vista and later systems by modifying the SSL cipher suite. For a step-by-step guide in applying workarounds, click here. 

The security vulnerability is under investigation. Microsoft will provide security updates where applicable. 

Local Community Advertising

Trending Stories

Woman who murdered BC teen thinks TV show about her crime is 'disrespectful': Parole documents

4 BC breweries earn hardware at 2024 World Beer Cup

RCMP searching for BC woman who has not been heard from in 'many months'

'Trump-style politics': NDP MLA on John Rustad's plan to compensate BC's unvaccinated healthcare workers

Downtown Kelowna clothing company celebrating 5 years in business

'It's terrifying': Man stabbed to death in BC city days after random knife attack in same area

Fire bans announced in BC and Alberta as more than 170 wildfires burn

'An incredible violation': CSIS had officer investigated after she reported a superior raped her in BC