Using a secure connection, or HTTPS connection, may be necessary to secure users' financial transactions , but it is not particularly effective in protecting their privacy.
American researchers have found that analyzing web traffic from websites that use HTTPS can yield personal user data, potentially related to medical conditions and financial or legal matters.
More specifically, researchers Brad Miller, AD Joseph, JD Tygar, and Ling Huang demonstrated that even encrypted web traffic can be analyzed, revealing information about the pages that users view.
To conduct the research, “traffic analysis attacks” were carried out on ten websites, including Netflix, YouTube, as well as websites of financial and legal services organizations, banks, and hospitals.
The web traffic analysis involved 6,000 individual subdomains of the above websites and had 90% accuracy in matching users with the pages they visited.
The attack is not simple. As the researchers note, “the attacker must be able to visit the same websites as the target, and have the ability to capture the victim’s traffic. In this way, the attacker can identify patterns in the encrypted traffic that can be matched to the pages that he and the victim visited.”.
"However, Internet providers, and by extension governments through surveillance services, have exactly this picture of user traffic," the researchers point out.

