HomeSecurity95% of HTTPS connections can be easily hacked

95% of HTTPS connections can be easily compromised

The inability or even negligence of server admins to properly configure the HTTP Strict Transport Security (HSTS) protocol is the reason why a large portion of today's HTTPS traffic can be compromised through trivial attacks.

 HTTPS hacking

HSTS is essentially a web security policy supported by most modern browsers. HSTS helps webmasters effectively protect their services and users against HTTPS downgrades, man-in-the-middle attacks, and cookie hijacking of HTTPS connections.

According to a recent study by Netcraft, 95% of all servers running HTTPS fail to properly implement HSTS, or include errors in their configuration settings, which make server-client connections vulnerable to the aforementioned attack scenarios.

What's even more interesting is that the percentage of correct HSTS usage has remained flat over the past three years, according to Netcraft's metrics. This suggests that webmasters are either unaware that they are implementing HSTS incorrectly, or simply don't care.

The easiest attack scenario against insecure websites is HTTPS downgrade, in which attackers can use multiple methods to force a seemingly secure HTTPS connection to use no encryption or to use a weaker certificate, which can be attacked and cracked later.

According to security researchers, among the 95% of websites that fail to properly implement HSTS, many banks and websites that implement financial transactions are included.

You can enable HTST by adding a line to the server config file

HTST is implemented by adding a single line of code to the server configuration:

Strict-Transport-Security: max-age=31536000;

based on which the server instructs browsers to access its contents only via HTTPS connections and sets a maximum keep-alive value of one year.

When this setting is active, even if the user types the prefix “http://” in the URL bar, the browser will automatically change it to “https://” upon request from the server.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS