Showing posts with label Android Browsers. Show all posts
Showing posts with label Android Browsers. Show all posts

Friday, 6 March 2015

Microsoft Warns Of TLS / SSL Vulnerability In Windows


Not only Android and Apple users at risk revealed by this week " FREAK attack "on TLS / SSL, even Windows users are vulnerable, so let Microsoft know . Through the leak, an attacker who is between a target and the Internet is in some cases the encryption of the encrypted connection to downgrade to a weak encryption to crack then that and to see the encrypted traffic.

Initially it was claimed that Apple TLS / SSL clients such as Safari, and the standard Android browser were vulnerable.According to Microsoft, the problem is also present in all supported versions of Windows. In order to succeed, the attack is also requires that the server that the user a secure connection setup supports "RSA key exchange export ciphers". Research among 14 million websites shows that this at 36.7% is still the case. Several Internet companies, however, have indicated that export-grade encryption to phase out.

Or Microsoft comes up with an emergency patch for the problem is still unknown. The software giant says to investigate the problem and on that basis to decide whether an emergency patch appears that the update through the monthly patch cycle is distributed. Microsoft claims to have no information to suggest that Windows users have been attacked by the vulnerability. In anticipation of the update, Windows Users weak encryption itself off . However, this can ensure that Windows can not connect to systems that support only weak encryption.

Researchers develop Freakattack.com that are far more vulnerable browsers than assumed initially. On the website you will find a list of vulnerable clients. It comes to Internet Explorer, Chrome on Mac OS, Chrome on Android, Safari on Mac OS X, Safari on iOS, the default Android browser, Blackberry browser, Opera on Mac OS X and Opera on Linux. Chrome on Mac OS is now an update available. Updates for Safari should appear next week.

Monday, 19 January 2015

Android Jelly Bean - "Expert Warns Of Default Android Browser"


An American security expert has nearly a billion users with Android Jelly Bean or an older version of the mobile operating system works warned to stop using the standard supplied browser and other browsers to switch.

The reason is that vulnerabilities in the WebView component of the AOSP (Android Open Source Project) -Browser not be patched by Google. Monday warned Todd Beardsley security company Rapid7 that no new updates come out more WebView. WebView is an important part of Android for displaying web pages. It is a separate browser window that developers can use their apps and allows to websites and pages within the screen layout of the application again.

In the latest versions of Android WebView is no longer used, but 60% of Android users is still a version where this is the case. It may therefore be years before WebView is gone everywhere and all the time users run risk, notes Beardsley. "If I were an attacker and had to choose an Android component to attack, it would be WebView. WebView is a component that is used in almost all ad-supported libraries, as well as when you are in any web app not rendering" Open link in browser "click."

The expert is therefore surprised that Google still deliver more updates for example, the audio player in older Android versions, but WebView a miss. Since Chrome, Firefox and other browsers no WebView This is an important security measure notes Beardsley. "If your default browser on AOSP Jelly Bean or earlier, then stop." The same advice applies to users who use the older browser their telecom provider. However, the vulnerable component also appears to affect all kinds of apps and ad networks, as suggested anti-virus company Trend Micro fixed earlier.