Skip to main content

New HTTPS exploit leaves hundreds of sites vulnerable, but there’s an easy fix

Researchers at INRIA, the French national research institute for computer science, have devised a new way to decrypt secret cookies which could leave your passwords vulnerable to theft.

Karthikeyan Bhargavan and Gaetan Leurent, have devised and carried out an attack – in a crypto research lab – which can pirate traffic from over 600 of the web’s most popular sites and lay bare your previously secure login information.

Recommended Videos

The exploit, dubbed ‘Sweet32’, isn’t easy to carry out, however. It involves mining hundreds of gigabytes of data, and targeting specific users who have accessed a malicious website which saddled them with a bit of malware. Still, the difficulty in carrying out the attack is outweighed by just how completely it subverts some of the internet’s most common encryption schemes.

While the attack is very difficult to carry out in practice, the existence the exploit has security experts on the OpenSSL development team taking notice.

By mining HTTPS or OpenVPN encrypted traffic, the researchers were able to use a mathematical paradox to identify portions of encrypted information and decipher login and password credentials in their entirety.

Don’t panic just yet, security experts speaking with Ars Technica are convinced that the threat posed by the exploit is minimal, in part due to the fact that it’s got a relatively simple fix.

The key vulnerability exploited in the secret-cookie-decryption-scheme is only found in 64-bit block ciphers, which OpenVPN developers have already addressed in the most recent version of their VPN software. Other security experts speaking with Ars have confirmed that the exploit poses little threat as long as developers get on board and stop using 64-bit block ciphers like Triple DES, or ‘3DES’.

“The 3DES issue is of little practical consequence at this time. It is just a matter of good hygiene to start saying goodbye to 3DES,” said Viktor Dukhovni, a member of the OpenSSL team.

Jaina Grey
Former Digital Trends Contributor
Jaina Grey is a Seattle-based journalist with over a decade of experience covering technology, coffee, gaming, and AI. Her…
These two macOS 26 features would transform the way I use my Mac
Writing tools in Apple Notes.

Apple’s execution with note-taking on macOS leaves a lot of room for improvement. There are so many areas where it feels like an abandoned project, instead of the future-proof experience that native iOS apps often deliver. In fact, the disparity across its own platforms is troubling. 

Take, for example, iPadOS and iOS. You can quickly launch a notes page straight from the control, without having to close the existing app and launch the Notes app. On macOS, you don’t get any such facility. 

Read more
Looking for a 2-in-1 laptop? The Samsung Galaxy Book 5 Pro 360 is $250 off
Samsung Galaxy Book5 Pro 360 front view showing tend mode.

Samsung is a brand that's better known for its smartphones and TVs, but it also has fantastic laptop deals, like this one for the Samsung Galaxy Book 5 Pro 360. You can currently get this 2-in-1 laptop with a $250 discount, which slashes its price from $1,700 to $1,450. We're not sure how much time is remaining on this offer though, so if you're interested in buying this premium device but you want to get it for a lower price than usual, you're going to have to proceed with your purchase immediately.

Why you should buy the Samsung Galaxy Book 5 Pro 360 2-in-1 laptop

Read more
Upgrade to this Alienware 4K QD-OLED gaming monitor while it’s $300 off
Cyberpunk 2077 being played on the Alienware 32 QD-OLED.

The powerful machine you purchased from gaming PC deals should be paired with a premium display, and the 32-inch Alienware 4K QD-OLED gaming monitor comes with our stamp of approval. It's also on sale from Dell right now, with a $300 discount slashing its price from $1,200 to only $900. That's a steal when you consider the capabilities of this screen, so you're going to have to hurry with your purchase as stocks may run out at any moment.

Why you should buy the 32-inch Alienware 4K QD-OLED gaming monitor

Read more