At the recent Black Hat conference , researchers presented a new attack that can bypass HTTPS connections. They named it “ BREACH ,” which stands for “ Browser Reconnaissance and Exfiltration via Adaptive Compression of Hypertext .” The attack method can be used to steal sensitive information from HTTPS connections in just a few seconds.
Salesforce.com's Chief Security Product Officer and Technical Officer Angelo Prado, Square's Chief Security Officer Neal Harris, and Salesforce.com's Chief Technical Officer Yoel Gluck are the ones who discovered and presented the attack method.
“It depends on the attacker being able to observe the size of the ciphertext received from the browser, while triggering a series of strategically crafted requests to the targeted website,” states a Prado post explaining the vulnerability published toUSA CERT.
"To recover secret information from HTTPS connections, an attacker would have to guess one character at a time, and send two requests for each guess they make. A correct guess will result in a lower response time for the HTTPS connection.".
“If the magnitude of the first response is smaller than the second, this indicates that the first hypothesis has a very good chance of being the correct one.”
