Skip to main content

Security researchers find yet another leak in HTTPS, and it won’t be easy to patch

A new attack has the potential to steal everything from email addresses to social security numbers — and security experts have found it running free in the wild. It works by manipulating the way HTTPS responses are delivered across the transmission control protocol (TCP), allowing nefarious actors to decrypt hidden information to extract personal data on targeted users.

The exploit is known as HEIST, which loosely stands for HTTP Encrypted Information can be Stolen Through TCP-Windows (as per Ars) and it’s especially dangerous because it’s capable and simple. When a web user encounters the malicious coding on a web page, it is able to query a number of pages, measuring the sizes of the data that is transmitted when the response comes in.

Recommended Videos

Although that data is protected by HTTPS, using older exploits, nefarious actors may be able to decrypt the data in those packets and thereby discover quite personal data about the individuals affected.

Fortunately the technique was devised by security researchers at the University of Leuven, Belgium, rather than by black-hats. That’s why we’re hearing about it before it’s been utilized for privacy invasions in the wild. The researchers who discovered the exploit, Van Goethem and Mathy Vanhoef, previously disclosed it to both Microsoft and Google, but proved its viability again yesterday by tacking on dangerous code to a New York Times advert.

The pair believe that in the right hands, the security flaw could affect many websites and by extension, many, many users.

Unfortunately, at this time a proper fix doesn’t really exist. End users can disable cookies, which just about makes it impossible for data it sends to be decrypted, but that would also kill the functionality on a lot of sites.

Considering HEIST is merely the means to an end and the exploits that allow the decryption of the HTTPS data have been around for years, this doesn’t seem like a security hole that is going to be patched any time soon. Security researchers aren’t hopeful, either.

Unfortunately this means we’re all left swinging in the wind with how to best protect ourselves. The only positive to it all is that since we need to stumble across malicious code to become vulnerable, sticking to reliable websites which are unlikely to host it is the best way to protect yourself, short from disabling cookies everywhere and walling yourself off from the online world.

Jon Martindale
Former Digital Trends Contributor
Jon Martindale is a freelance evergreen writer and occasional section coordinator, covering how to guides, best-of lists, and…
Every macOS version in order: from the first public beta to macOS 15
Apple MacBook Air 15 M4 front angled view showing display and keyboard.

Apple’s macOS operating system has changed a lot over the last 25 years, with new features and designs coming and going as the decades have passed. Even the name has been adjusted, starting out as Mac OS X before shortening to OS X and eventually settling on macOS. The world the original version inhabited back in 2000 is very different to today.

Including the initial public beta, Apple has released 22 versions of the Mac operating system so far, with new launches becoming an annual occurrence. But it wasn’t always this way, and there have been some fascinating updates and developments in the time since the first version appeared. Let’s see how macOS has changed over the years.

Read more
I tested Microsoft’s controversial Recall tool. It evolved Windows for me.
Running Windows 11 Recall on a Copilot+ PC.

Imagine a tool that takes an image of whatever appears on your computer’s screen, saves it locally, and lets you access it all like a time machine. A magical looking glass for the computing past. That’s essentially what Microsoft’s Recall is all about. Yet, when it was first introduced, it stirred up a security storm.

Microsoft pulled its release plans, fortified the security guardrails, and relaunched it a few weeks ago. This time around, Recall got a minor-but-amazingly practical upgrade. The best part? Instead of having you scrub through a long timeline of pictures, you can simply search through the entire activity history with words.

Read more
Dell sale: Up to $400 off monitors, desktop PCs, laptops, and more
Alienware Aurora R16 sitting on a coffee table.

Dell is always an excellent source of monitor deals, desktop computer deals, and laptop deals, especially if you're able to take advantage of the savings from Dell sales -- just like the one that's happening right now. Feel free to take a look at everything that's available through the link below, but you can also check out our favorite offers that we've rounded up. Either way, we highly recommend hurrying with your purchase -- these limited-time deals will only last until May 25, but there's a chance that stocks for the more popular devices will sell out long before then.

Alienware Aurora R16 gaming PC -- $2,450 $2,850 14% off

Read more