HomeSecurityBlackBerry suffers FREAK attack on its products

BlackBerry suffers FREAK attack on its products

BlackBerry

A large number of BlackBerrywere found vulnerable to the attack known as  FREAK (Factoring RSA Export Keys), as revealed earlier this month. The company. However, it has not yet released a patch to fix the vulnerability.

The FREAK attack downgrades the SSL/TLSto a weaker variant (RSA 512-bit), which can be easily cracked with today's technology, in about seven hours. This is an old encryption specification from 1990, when there was a restriction, which lasted until 1992, on the levels of encryption available in hardware and software on devices exported from the United States. However, the attacker would have to compromise the connection between the client and the server.

Several different SSL/TLS protocols were found to be affected by the attack, including OpenSSL, which is included in BlackBerry products. A new updated version of OpenSSL was released to fix the issue there.

On Thursday, BlackBerry announced that although a large portion of its software was affected by the vulnerability, there is currently no information that it will release fixes for the problem.

The list of products vulnerable to the FREAK attack includes the operating system, BlackBerry Enterprise Server, Secure Work Space, Work Browser, Work Connect, BlackBerry Blend, all versions of BBM on BlackBerry 10 and Windows Phone, as well as versions lower than 2.7.0.6 for Android and 2.7.0.32 for iOS.

According to the company's latest announcement on the matter, the entire technical team is working to fully determine the systems affected by the FREAK attack, and find the best solution for customer security.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS