Tuesday, March 10, 2026
  • About us
    • Write for us
    • Disclaimer
    • Terms of use
    • Privacy Policy
  • RSS Feeds
  • Advertise with us
  • Contact us
DefenceTalk
  • Home
  • Defense News
    • Defense & Geopolitics News
    • War Conflicts News
    • Army News
    • Air Force News
    • Navy News
    • Missiles Systems News
    • Nuclear Weapons
    • Defense Technology
    • Cybersecurity News
  • Military Photos
  • Defense Forum
  • Military Videos
  • Military Weapon Systems
    • Weapon Systems
    • Reports
No Result
View All Result
  • Home
  • Defense News
    • Defense & Geopolitics News
    • War Conflicts News
    • Army News
    • Air Force News
    • Navy News
    • Missiles Systems News
    • Nuclear Weapons
    • Defense Technology
    • Cybersecurity News
  • Military Photos
  • Defense Forum
  • Military Videos
  • Military Weapon Systems
    • Weapon Systems
    • Reports
No Result
View All Result
DefenceTalk
No Result
View All Result
Home Defence & Military News Technology News

Newly found online security flaw stems from 1990s

by Agence France-Presse
March 4, 2015
in Technology News
2 min read
0
Malware hunter Kaspersky warns of cyber war dangers
14
VIEWS

A newly discovered Internet security flaw could leave many websites vulnerable to hackers because of weak US encryption standards in the 1990s, researchers said Tuesday.

The flaw dubbed “FREAK” could leave thousands of websites open to attacks if the problem is not patched, according to papers released by French and US researchers.

The flaw was discovered by a team led by Karthikeyan Bhargavan at INRIA in Paris — the French Institute for Research in Computer Science and Automation — and disclosure coordinated by Matthew Green, a cryptographer at Johns Hopkins University.

A research paper said the flaw comes from “a class of deliberately weak export cipher suites… introduced under the pressure of US government agencies to ensure that the NSA would be able to decrypt all foreign encrypted communication.”

Green said in a blog post that even some sites maintained by the National Security Agency and FBI appeared to be vulnerable.

“Since the NSA was the organization that demanded export-grade crypto, it’s only fitting that they should be the first site affected by this vulnerability,” Green said.

Green and other researchers said the flaw stems from US government-imposed standards for encryption in software that was exported — a short-lived effort to allow the United States to be able to access software exported to unfriendly regimes.

Part of the software
Even after it became legal to export strong encryption, the export mode feature was not removed from because some software still depended on it, according to Ed Felten, a Princeton University computer science professor.

“The flaw is significant in itself, but it is also a good example of what can go wrong when government asks to build weaknesses into security systems,” said Felten in a blog post.

“Many web sites are vulnerable to this attack, allowing an adversary in the network to spoof or spy on traffic to vulnerable sites.”

Felten said that the vulnerability on the NSA site is “not a big national security problem in itself because NSA doesn’t distribute state secrets from its public site. But there is an important lesson here about the consequences of crypto policy decisions.”

Green said Facebook’s site which operates the “like” button was identified as vulnerable but later patched.

Green said the most of the flaws “will soon be patched” but that the flaw is important at a time when the NSA is seeking to maintain access to encrypted software and devices for national security reasons.

“The moral of this story is pretty simple: Encryption backdoors will always turn around and bite you in the ass,” he wrote.

Tags: cyber securitynetwork securitysecurity
Previous Post

Boeing Sends First All-Electric Propulsion Satellites In Orbit

Next Post

Bell Helicopter Seals Deal for 15 Bell 407GXs to the Mexican Air Force

Related Posts

OpenAI robotics manager resigns over Pentagon deal

OpenAI robotics manager resigns over Pentagon deal

March 10, 2026

A robotics manager at OpenAI said Saturday that she had resigned over the artificial intelligence giant's deal with the US...

Anthropic takes Trump administration to court over Pentagon row

Anthropic takes Trump administration to court over Pentagon row

March 10, 2026

Anthropic filed suit Monday against the Trump administration, alleging the US government retaliated against the AI company for refusing to...

Next Post
Bell Helicopters

Bell Helicopter Seals Deal for 15 Bell 407GXs to the Mexican Air Force

Latest Defense News

Patriot missile defense system deployed in central Turkey

March 10, 2026
Iran unveils ballistic missile, ‘new generation’ engines

Iran says missile attacks to continue, US talks ‘not on agenda’

March 10, 2026
OpenAI robotics manager resigns over Pentagon deal

OpenAI robotics manager resigns over Pentagon deal

March 10, 2026
Anthropic takes Trump administration to court over Pentagon row

Anthropic takes Trump administration to court over Pentagon row

March 10, 2026
Sikorsky Ramps Up Production of New Variant S-92 Helicopter

Sikorsky Ramps Up Production of New Variant S-92 Helicopter

March 9, 2026
Qatar arrests 313 people for sharing attacks footage, ‘rumors’

Qatar arrests 313 people for sharing attacks footage, ‘rumors’

March 9, 2026

Defense Forum Discussions

  • Middle East Defence & Security
  • General Naval News
  • Indonesian Aero News
  • Royal Australian Navy Discussions and Updates 2.0
  • 6th Generation Fighters Projects
  • Military Aviation News and Discussion
  • ADF General discussion thread
  • Japan Ground Self Defense Force
  • Japan Air Self-Defence Force
  • The Russian-Ukrainian War Thread
DefenceTalk

© 2003-2020 DefenceTalk.com

Navigate Site

  • Defence Forum
  • Military Photos
  • RSS Feeds
  • About us
  • Advertise with us
  • Contact us

Follow Us

No Result
View All Result
  • Home
  • Defense News
    • Defense & Geopolitics News
    • War Conflicts News
    • Army News
    • Air Force News
    • Navy News
    • Missiles Systems News
    • Nuclear Weapons
    • Defense Technology
    • Cybersecurity News
  • Military Photos
  • Defense Forum
  • Military Videos
  • Military Weapon Systems
    • Weapon Systems
    • Reports

© 2003-2020 DefenceTalk.com