HomeSecurityUsing HTTPS is not enough to protect user privacy...

Using HTTPS is not enough to protect user privacy

digital-web-background

Using a secure connection, or HTTPS connection, may be necessary to secure users' financial transactions , but it is not particularly effective in protecting their privacy.

American researchers have found that analyzing web traffic from websites that use HTTPS can yield personal user data, potentially related to medical conditions and financial or legal matters.

More specifically, researchers Brad Miller, AD Joseph, JD Tygar, and Ling Huang demonstrated that even encrypted web traffic can be analyzed, revealing information about the pages that users view.

To conduct the research, “traffic analysis attacks” were carried out on ten websites, including Netflix, YouTube, as well as websites of financial and legal services organizations, banks, and hospitals.

The web traffic analysis involved 6,000 individual subdomains of the above websites and had 90% accuracy in matching users with the pages they visited.

The attack is not simple. As the researchers note, “the attacker must be able to visit the same websites as the target, and have the ability to capture the victim’s traffic. In this way, the attacker can identify patterns in the encrypted traffic that can be matched to the pages that he and the victim visited.”.

"However, Internet providers, and by extension governments through surveillance services, have exactly this picture of user traffic," the researchers point out.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS