FREAK

Last reviewed:

FREAK (Factoring RSA Export Keys) is a security vulnerability that affected SSL/TLS protocols, allowing attackers to intercept and decrypt secure communications. Discovered in 2015, FREAK exploited a weakness in the cryptographic standards used by web browsers and servers, particularly those that supported outdated export-grade encryption. This vulnerability primarily impacted devices using OpenSSL and Apple’s Secure Transport, affecting millions of users worldwide. As of October 2023, FREAK is considered a historical vulnerability, with most systems having been patched to mitigate the risk.

Overview

FREAK was identified as a vulnerability in the SSL (Secure Sockets Layer) and TLS (Transport Layer Security) protocols, which are used to secure communications over the internet. The vulnerability exploited the use of weak export-grade cryptographic keys, which were originally implemented due to U.S. government regulations in the 1990s that restricted the export of strong encryption technologies. These export-grade keys were significantly weaker than standard keys, making them susceptible to attacks. FREAK allowed attackers to force a downgrade of encryption strength during the SSL/TLS handshake, enabling them to intercept and decrypt communications between clients and servers.

How it works

FREAK exploited a flaw in the way SSL/TLS protocols handled cryptographic keys. During the SSL/TLS handshake, the client and server negotiate the encryption algorithm and key strength to be used for the session. FREAK took advantage of servers that still supported export-grade RSA (Rivest-Shamir-Adleman) keys, which are 512 bits in length and much weaker than modern standards. Attackers could intercept the handshake and force the use of these weaker keys. Once the connection was downgraded, attackers could factor the weak RSA keys using available computational resources, decrypt the session, and access sensitive information such as passwords, credit card numbers, and other personal data.

Applications

The primary application of the FREAK vulnerability was in intercepting and decrypting secure communications. It posed a significant threat to the confidentiality and integrity of data transmitted over the internet. The vulnerability affected a wide range of devices and software, including web browsers, mobile devices, and servers. Notably, it impacted popular browsers like Safari and Internet Explorer, as well as Android and iOS devices. Organizations using vulnerable systems risked exposure of sensitive customer data, to potential financial and reputational damage.

Limitations

While FREAK was a serious vulnerability, it had several limitations. First, it required the presence of a vulnerable server that supported export-grade cryptography. As more organizations updated their systems to support stronger encryption, the number of vulnerable servers decreased. Additionally, exploiting FREAK required significant computational resources to factor the weak RSA keys, making it less feasible for attackers without access to such resources. Finally, the vulnerability was quickly addressed by major software vendors, who released patches to disable support for export-grade cryptography, reducing the risk of exploitation.

FREAK Vulnerability Exploitation Process

Timeline of FREAK Vulnerability

See also

  • SSL/TLS
  • Cryptography
  • Vulnerability

Sources

Categories: Vulnerabilities
Last updated: October 3, 2026