Advertisement

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

PA Wire/Press Association Images

Millions of Apple and Google customers are vulnerable to a decades-old hack

Hackers may be harvesting your sensitive personal information.

MILLIONS OF APPLE  and Google customers are at risk of having their confidential details stolen by hackers thanks to a newly-discovered “FREAK” vulnerability, the Washington Post reports.

The security flaw affects Android and iOS users who use the default Chrome or Safari browsers. Both companies are now rushing to bring out a fix.

So what is “FREAK”?

It stands for Factoring attacks on RSA-EXPORT Keys. To understand what that it is, you need to know about the history of cryptography.

Back in the 1990s, there was a debate over the use of cryptography to secure websites. Researchers and developers argued it was essential to protect people’s confidential details, while the authorities argued it threw up dangerous barriers to law enforcement.

Ultimately, a limit of 512-bit was placed on the strength of encryption in software that could be exported from America.

Encryption

This meant authorities could, if need be, intercept communications of products that has this encryption strength. These limits were later relaxed and encryption became considerably stronger. But the early restrictions had a nasty effect.

“The weaker encryption got baked into widely used software that proliferated around the world and back into the United States, apparently unnoticed until this year,” The Washington Post explains.

This means that many websites and browsers are still programmed to provide 512-bit keys for security when requested, even though they can be cracked in a matter of hours.

As a result, a hacker could go to an affected website, obtain its weak key, crack it, then be able to impersonate that website and intercept traffic to the site on the same network as them.

It’s what’s often called a “man in the middle” attack. On your home WiFi you’re probably safe, but you could be targeted whenever you log on to a public network, like a a coffee shop, or a hotel, or an airport.

Websites 

The list of websites affected is extremely extensive.

Banks like American Express and Santander are vulnerable, along with other major websites like Groupon, hotel chain Marriott, and shopping site J-Crew.

At one point, the websites of the White House, the NSA, and the FBI were all affected, according to the Washington Post, although they’ve since implemented fixes.

According to one site dedicated to tracking FREAK, 9.7% of the Alexa Top 1 Million websites are affected (down from 12.2% as people begin to patch the issue).

What this means in real terms is that when you’re shopping online, or checking your bank statement, or logging onto one of your favourite sites, hackers may be harvesting your sensitive personal information.

There’s no confirmed uses of FREAK to harvest personal data — but the vulnerability has existed for decades, so it’s not unthinkable to suggest it may have been used.

And the reason FREAK exists isn’t because of shoddy coding by a developer — it’s because the government wanted a “backdoor” into encryption products when necessary.

As debate over the use of encryption begins to flare up once again, researchers are already pointing to FREAK as evidence developers shouldn’t weaken their encryption products at the request of law enforcement.

“Encryption backdoors will always turn around and bite you in the ass,” writes Matthew Green. “They are never worth it.”

Read: This is the mobile browser Apple should have made>

Read: This heartwarming video uses an X-ray machine to get its message across>

Readers like you are keeping these stories free for everyone...
A mix of advertising and supporting contributions helps keep paywalls away from valuable information like this article. Over 5,000 readers like you have already stepped up and support us with a monthly payment or a once-off donation.

Published with permission from
View 15 comments
Close
15 Comments
    Install the app to use these features.
    Mute Red Pirate 71
    Favourite Red Pirate 71
    Report
    Sep 21st 2019, 2:06 PM

    Serious injuries because the state refuses to legalize fireworks but prefers thousands of them to be let off illegally. Same with drugs. Leave it to the underworld to police that too. Dumb and dumber.

    258
    Install the app to use these features.
    Mute Paul
    Favourite Paul
    Report
    Sep 21st 2019, 2:10 PM

    @Red Pirate 71: serious injuries because someone brought illegal explosives into the country which were used illegally by untrained individuals. Personal responsibility goes a long way, it’s not the states fault all the time!

    966
    Install the app to use these features.
    Mute Chin Feeyin
    Favourite Chin Feeyin
    Report
    Sep 21st 2019, 2:13 PM

    @Red Pirate 71: how would legalising fireworks prevent accidents like this?

    Next you’ll be blaming the government for the weather.

    457
    See 15 more replies ▾
    Install the app to use these features.
    Mute Richie Kennedy
    Favourite Richie Kennedy
    Report
    Sep 21st 2019, 2:17 PM

    @Red Pirate 71: How can you blame the government for teenagers being idiots?

    267
    Install the app to use these features.
    Mute Luap
    Favourite Luap
    Report
    Sep 21st 2019, 2:38 PM

    @Chin Feeyin: Because the fireworks they could buy then would be regulated and have proper safety standards attached to them. I guarantee what caused this was some shitty black cat banger from the black market.

    34
    Install the app to use these features.
    Mute Stephen Blood
    Favourite Stephen Blood
    Report
    Sep 21st 2019, 2:44 PM

    @Luap: most fireworks are bought in the north

    60
    Install the app to use these features.
    Mute Gisbert Bayertz
    Favourite Gisbert Bayertz
    Report
    Sep 21st 2019, 3:07 PM

    @Red Pirate 71: so you’re blaming the state for the stupid actions of two fellows who are old enough to know better?

    147
    Install the app to use these features.
    Mute Just Some Guy
    Favourite Just Some Guy
    Report
    Sep 21st 2019, 3:13 PM

    @Red Pirate 71:

    Personal responsibility.

    129
    Install the app to use these features.
    Mute Peter Mulligan
    Favourite Peter Mulligan
    Report
    Sep 21st 2019, 4:44 PM

    @Chin Feeyin: Everyone knows the government is to blame for the weather !

    30
    Install the app to use these features.
    Mute Sisi R
    Favourite Sisi R
    Report
    Sep 21st 2019, 6:28 PM

    @Richie Kennedy: because he is from that part of society himself.

    8
    Install the app to use these features.
    Mute Gavin Scott
    Favourite Gavin Scott
    Report
    Sep 21st 2019, 6:53 PM

    @Luap: that’s pure speculation. Fireworks are dangerous in any kids’ hands. Also dangerous in the hands of untrained adults.

    13
    Install the app to use these features.
    Mute EillieEs
    Favourite EillieEs
    Report
    Sep 21st 2019, 8:39 PM

    @Red Pirate 71: ‘cos no one in countries where fireworks are legal has ever been injured?

    15
    Install the app to use these features.
    Mute Anthony Doyle
    Favourite Anthony Doyle
    Report
    Sep 22nd 2019, 2:42 AM

    @Red Pirate 71: and dumbest

    2
    Install the app to use these features.
    Mute Cupid Stunt
    Favourite Cupid Stunt
    Report
    Sep 22nd 2019, 5:28 AM

    @Luap: You guarantee it do you?

    1
    Install the app to use these features.
    Mute STOIC SAVAGE
    Favourite STOIC SAVAGE
    Report
    Sep 22nd 2019, 8:19 AM

    @Red Pirate 71: this is by far the most idiotic comment ive ever seen… What a dope!!!

    1
    Install the app to use these features.
    Mute Noj Nikrub
    Favourite Noj Nikrub
    Report
    Sep 22nd 2019, 12:06 PM

    @Red Pirate 71: it’s legal in the uk and they never have firework accidents!

    1
    Install the app to use these features.
    Mute Ann Reddin
    Favourite Ann Reddin
    Report
    Sep 22nd 2019, 4:57 PM

    @Paul: It is very much the states responsibility to police this, they after all, are the ones who put the legislation in place. Wouldn’t be surprised if you are one of those people who buy fireworks on the black market for Halloween night.

    1
    Install the app to use these features.
    Mute Disabled Junkie
    Favourite Disabled Junkie
    Report
    Sep 23rd 2019, 3:10 PM

    @Paul: If the state prohibits something they create a black market. Black market dealers will sell to children! Were fireworks legal and sold in shops, you would be able to have laws to restrict children from buying them.

    1
    Install the app to use these features.
    Mute ros aodha
    Favourite ros aodha
    Report
    Sep 21st 2019, 5:56 PM

    Zero sympathy unless they were subjected of an actual accident, on the other hand if they did this to themselves whilst mucking around illegally with illegal fireworks… well, Darwin always wins.

    92
    Install the app to use these features.
    Mute Dotty Mc Dot
    Favourite Dotty Mc Dot
    Report
    Sep 22nd 2019, 5:15 PM

    @ros aodha: they are only kids you muppet. Be careful what you write . Family members could be reading this. Fool

    4
    Install the app to use these features.
    Mute ken gray
    Favourite ken gray
    Report
    Sep 21st 2019, 4:32 PM

    Cabra fireworks intimidation of innocent people gangs on bikes lawless living off the state I’m entitled give me everything now and I will promise to be vermin leeching off the state right to the end !

    131
    Install the app to use these features.
    Mute Liam Ó hAodha
    Favourite Liam Ó hAodha
    Report
    Sep 21st 2019, 2:43 PM

    Apparently one lad lost a couple of fingers, the other an eye.

    64
    Install the app to use these features.
    Mute In my opinion
    Favourite In my opinion
    Report
    Sep 21st 2019, 5:53 PM

    @Liam Ó hAodha: ah well.

    44
    Install the app to use these features.
    Mute John Mulligan
    Favourite John Mulligan
    Report
    Sep 21st 2019, 3:19 PM

    So?

    32
    Install the app to use these features.
    Mute Devilsavocado
    Favourite Devilsavocado
    Report
    Sep 21st 2019, 6:38 PM

    Anyone see the video going around with the AC Milan fan(I think) losing a hand thanks to a firework,, gruesome to say the least… :(

    10
    Install the app to use these features.
    Mute Dave Forde
    Favourite Dave Forde
    Report
    Sep 21st 2019, 10:06 PM

    @Devilsavocado: ya looks cool

    1
    Install the app to use these features.
    Mute Susanne Morgan
    Favourite Susanne Morgan
    Report
    Sep 21st 2019, 11:44 PM

    They were setting off fireworks ‘on the southside’ as well yesterday – could only hear them, but one sounded like a lovely sparkely one – only it was in the middle of the afternoon in bright sunshine … what a waste

    8
    Install the app to use these features.
    Mute Dave Forde
    Favourite Dave Forde
    Report
    Sep 21st 2019, 10:07 PM

    Well if you play with fire……

    9
    Install the app to use these features.
    Mute Kerrydone
    Favourite Kerrydone
    Report
    Sep 22nd 2019, 3:06 AM

    Been gangs of these youths setting them off around pearse street since mid august, aiming them at people passing by. Gards dont seem to be doing anything to stop it

    8
    Install the app to use these features.
    Mute clairebear
    Favourite clairebear
    Report
    Sep 22nd 2019, 1:11 AM

    I was getting off the Luas at Broadstone yesterday evening when a group of teenagers let off proper fireworks beside the track. They exploded at ground level. I was thinking they could’ve seriously injured someone. One girl walking beside them got such a fright. Wonder if it was the same group they were on the green Luas line to Cabra

    7
    Install the app to use these features.
    Mute Jesse James
    Favourite Jesse James
    Report
    Sep 21st 2019, 3:18 PM

    The Dumb F**kers were messing with Explosives, shit happens when your that thick.

    216
    Install the app to use these features.
    Mute Marie McG
    Favourite Marie McG
    Report
    Sep 21st 2019, 3:46 PM

    @Jesse James: Maybe learn how to spell ‘you’re’ before calling people dumb. And get some empathy while you’re at it too.

    74
    Install the app to use these features.
    Mute Martin Harte
    Favourite Martin Harte
    Report
    Sep 21st 2019, 5:14 PM

    @Marie McG: play stupid games win stupid prizes

    79
    Install the app to use these features.
    Mute Disabled Junkie
    Favourite Disabled Junkie
    Report
    Sep 23rd 2019, 3:11 PM

    Nobody is doing 5 years for lighting fireworks. What nonsense! You wouldn’t even get 5 years for murder in this country.

    1
    Install the app to use these features.
    Mute Manni
    Favourite Manni
    Report
    Sep 21st 2019, 2:04 PM

    It’s a little early for fireworks.
    Kids will be kids. Some have to learn the hard way.

    1
    Install the app to use these features.
    Mute Dr. Emmett Lathrop
    Favourite Dr. Emmett Lathrop
    Report
    Sep 21st 2019, 2:48 PM

    Two more candidates for the Darwin Awards :-)

    1
    Install the app to use these features.
    Mute Manni
    Favourite Manni
    Report
    Sep 21st 2019, 2:06 PM

    Kids will be kids.
    Some have to learn the hard way.

    1
Submit a report
Please help us understand how this comment violates our community guidelines.
Thank you for the feedback
Your feedback has been sent to our team for review.
JournalTv
News in 60 seconds