Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Security researchers find yet another leak in HTTPS, and it won’t be easy to patch

Add as a preferred source on Google

A new attack has the potential to steal everything from email addresses to social security numbers — and security experts have found it running free in the wild. It works by manipulating the way HTTPS responses are delivered across the transmission control protocol (TCP), allowing nefarious actors to decrypt hidden information to extract personal data on targeted users.

The exploit is known as HEIST, which loosely stands for HTTP Encrypted Information can be Stolen Through TCP-Windows (as per Ars) and it’s especially dangerous because it’s capable and simple. When a web user encounters the malicious coding on a web page, it is able to query a number of pages, measuring the sizes of the data that is transmitted when the response comes in.

Recommended Videos

Although that data is protected by HTTPS, using older exploits, nefarious actors may be able to decrypt the data in those packets and thereby discover quite personal data about the individuals affected.

Fortunately the technique was devised by security researchers at the University of Leuven, Belgium, rather than by black-hats. That’s why we’re hearing about it before it’s been utilized for privacy invasions in the wild. The researchers who discovered the exploit, Van Goethem and Mathy Vanhoef, previously disclosed it to both Microsoft and Google, but proved its viability again yesterday by tacking on dangerous code to a New York Times advert.

The pair believe that in the right hands, the security flaw could affect many websites and by extension, many, many users.

Unfortunately, at this time a proper fix doesn’t really exist. End users can disable cookies, which just about makes it impossible for data it sends to be decrypted, but that would also kill the functionality on a lot of sites.

Considering HEIST is merely the means to an end and the exploits that allow the decryption of the HTTPS data have been around for years, this doesn’t seem like a security hole that is going to be patched any time soon. Security researchers aren’t hopeful, either.

Unfortunately this means we’re all left swinging in the wind with how to best protect ourselves. The only positive to it all is that since we need to stumble across malicious code to become vulnerable, sticking to reliable websites which are unlikely to host it is the best way to protect yourself, short from disabling cookies everywhere and walling yourself off from the online world.

Jon Martindale
Jon Martindale covers how to guides, best-of lists, and explainers to help everyone understand the hottest new hardware and…
Viture Pro 2 review: Affordable glasses that I loved more for work than play
One of the lightest and brightest XR glasses you will find for the price.
Viture Pro 2 smart glasses

Quick summary

Two years ago, I had the chance to test out the Viture Pro smart glasses. I was impressed by the chic design and the stunning display units, but there were a few minor hiccups that kept them from becoming an instant buy for XR fans. The asking price of $459, ultimately, made them a tough recommendation for anyone who is not a diehard enthusiast or doesn't have the spare cash to spend. The successor, however, is an altogether different beast.

Read more
Your Mac might have a screen sharing problem, and hackers already know about it
A patch is only useful once you install it.
macOS Tahoe 26 public beta running on the M4 MacBook Air 15

If you've been putting off that macOS update sitting in your notifications, this is the week to stop and install it. 

Apple quietly patched a serious screen sharing flaw in macOS earlier this month. While that usually means the issue is resolved, new evidence shows hackers already broke into unpatched Macs, hijacked them, and used them for cryptocurrency mining before the fix shipped.

Read more
The US is trying to kick foreign robots out, but the local supply chain might not be there yet
Building a robot supply chain from scratch takes years that Washington isn't giving anyone.
LG CLOiD Home Robot

The FCC has a track record of using its Covered List to squeeze Chinese tech out of American markets, and robots just became its newest target. Foreign-made humanoids, quadrupeds, and even robot vacuums now need to be mostly built in the U.S. to sell here (via Rest of World). 

So what does the new rule actually require?

Read more