Apple, Android devices vulnerable to hacks

A security flaw known as "FREAK attack" may have left people using Apple and Google devices on the web vulnerable to hackers.

Millions of people may have been left vulnerable to hackers while surfing the web on Apple and Google devices, thanks to a newly discovered security flaw known as "FREAK attack".

There's no evidence so far that any hackers have exploited the weakness, which companies are now moving to repair.

Researchers blame the problem on an old government policy, abandoned over a decade ago, which required US software makers to use weaker security in encryption programs sold overseas due to national security concerns.

Many popular websites and some internet browsers continued to accept the weaker software, or can be tricked into using it, according to experts at several research institutions who reported their findings on Tuesday.

They said that could make it easier for hackers to break the encryption that's supposed to prevent digital eavesdropping when a visitor types sensitive information into a website.

About a third of all encrypted websites were vulnerable as of Tuesday, including sites operated by American Express, Groupon, Kohl's, Marriott and some government agencies, the researchers said.

University of Michigan computer scientist Zakir Durumeric said the vulnerability affects Apple web browsers and the browser built into Google's Android software, but not Google's Chrome browser or current browsers from Microsoft or Firefox-maker Mozilla.

Apple Inc and Google Inc both said on Tuesday they have created software updates to fix the "FREAK attack" flaw, which derives its name from an acronym of technical terms.

Apple said its fix will be available next week and Google said it has provided an update to device makers and wireless carriers.

A number of commercial website operators are also taking corrective action after being notified privately in recent weeks, said Matthew Green, a computer security researcher at Johns Hopkins University.


Share

2 min read

Published

Updated

Source: AAP



Share this with family and friends


Get SBS News daily and direct to your Inbox

Sign up now for the latest news from Australia and around the world direct to your inbox.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

Download our apps
SBS News
SBS Audio
SBS On Demand

Listen to our podcasts
An overview of the day's top stories from SBS News
Interviews and feature reports from SBS News
Your daily ten minute finance and business news wrap with SBS Finance Editor Ricardo Gonçalves.
A daily five minute news wrap for English learners and people with disability
Get the latest with our News podcasts on your favourite podcast apps.

Watch on SBS
SBS World News

SBS World News

Take a global view with Australia's most comprehensive world news service
Watch the latest news videos from Australia and across the world