HEIST attack breaches HTTPS in the browser

A new technique has been unveiled that can attack Transport Layer Security (TLS)-protected communications in web browsers to expose encrypted email addresses and other personally sensitive data.

Exploiting the vulnerability requires a multistage attack on HTTPS protected pages by inserting a tailored JavaScript file in a web ad or directly on a webpage that measures the exact size of the encrypted files that are being transmitted to users’ browsers.

Read more: http://www.itnews.com.au/news/heist-attack-breaches-https-in-the-browser-432667

Posted in Newsbytes

Leave a Reply