HomeSecurityIs your connection secure with HTTPS encryption?

Is your connection secure with HTTPS encryption?

HTTPSMost people use HTTPS encryption to ensure their internet connection is secure. In addition, many sites offer Transport Layer Security, or TLS, to encrypt data between your browser and the web servers it communicates with, in order to protect your data and privacy in general.

However, while we think we are protected, new research findings are coming to light , according to which a very large number of encrypted sites do not provide full protection.

According to the research, 5.5% of the top 10,000 HTTPS sites were found to have TLS vulnerabilities. These vulnerabilities are the result of improper implementation of the TLS encryption system and ineffective bug fixing in TLS and Secure Sockets Layer (the predecessor to TLS).

The worrying thing is that the sites still seem safe.

Researchers discovered these vulnerabilities while the browser had been updated, meaning the updates failed to address the issues, or even detect them.

To analyze the 10,000 sites, the researchers used TLS analysis techniques and developed some new ones. The vulnerabilities found were placed into three categories depending on their type.

The first category of vulnerabilities is not that dangerous. However, the other two categories are quite threatening as they can allow an attacker to decrypt data, and even modify it. That is, they allow “man in the middle” attacks. Meanwhile, HTTPS encryption was designed to counter such attacks.

The good news is that TLS vulnerabilities can be exploited by hackers, but they are not usually an attractive target. However, it is still worrying that they exist on seemingly secure sites.

A critical issue related to these vulnerabilities is the connection between sites, as vulnerabilities on one site can have consequences on others.

"When you have domains that are related to each other, then sensitive data and things like cookies can be exchanged between the domains, which means that when one of the two domains has a problem, the vulnerability can spread to the other," says one of the researchers.

To get an idea of ​​how common the correlations between domains are, the researchers found nearly 91,000 domains that are either subdomains or share information with the 10,000 sites they examined. This means that vulnerabilities can be transmitted to related domains.

Since these correlations cannot be avoided, it is essential that all vulnerabilities are identified and addressed quickly so that there are no impacts on the sites themselves that have them, but also on those related to them.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS