HTTPS Vulnerabilities Could Allow Attackers to Snoop on Your Data: Researchers

Advertisement
By Harpreet Singh | Updated: 29 March 2019 14:03 IST
Highlights
  • Security researchers have found HTTPS flaws in some of the top websites
  • Most of these flaws still remain undetected
  • Some flaws are minor while others have allow attackers to manipulate data

Security researchers have found HTTPS vulnerabilities amongst top 10,000 websites on the Internet

That little green padlock that appears on your browser's address bar looks reassuring. It means the website you're currently visiting uses HTTPS (Hypertext Transfer Protocol Secure) for a secure connection. HTTPS protects you against man-in-the-middle attacks, that ensures no one can see your passwords, search history, and other sensitive content. Almost all popular websites now use HTTPS to encrypt the data between your web browser and web servers it communicates with.

However, new research claims some websites using HTTPS are still leaving their connections exposed. Researchers at Ca' Foscari University of Venice in Italy and Tu Wien in Austria have analysed the top 10,000 websites that use HTTPS and found that nearly 5.5 percent of these are vulnerable to TLS (Transport Layer Security) exploits.

Advertisement

The communication protocol in HTTPS is encrypted using Transport Layer Security (TLS), previously known as Secure Sockets Layer (SSL). Researchers claim that the flaws they've discovered are a result of issues that crop up depending on how websites implement TLS encryption schemes. These websites may have also failed to patch known buds in TLS and SSL.

But when you're visiting such a website, the shiny green padlock will still appear on your browser's address bar. That's how subtle these flaws can be, they're hard to detect. These flaws normally go unnoticed, claim the security researchers who discovered them.

Advertisement

The flaws were discovered by using TLS analysis techniques to crawl and analyze the top 10,000 sites for TLS issues. The researchers picked up these websites from Alexa's ranking of top websites on the Internet.

These security flaws could potentially allow a malicious attacker to decrypt small information such as session cookies, but wouldn't be much useful in extracting something as sensitive as a password.

Advertisement

But there are some more 'leaky' flaws that could potentially allow attackers to decrypt almost all of the Web traffic passing between a browser and a Web server, according to the research paper.

Then there are 'tainted' vulnerabilities that could potentially enable attackers to decrypt and manipulate data being transferred between a browser and a web server. These man-in-the-middle attacks are exactly the reason why HTTPS was put into place.

Advertisement

Researchers claim that all the top 10,000 websites that were tested also include around 91,000 related domains. HTTPS vulnerabilities in these websites could increase the overall number of affected sites.

Vulnerabilities discovered that 898 websites, from the 10,000 total websites they tested, were fully compromisable while 977 websites presented low integrity pages. The full research paper will be presented at the 40th IEEE Symposium on Security and Privacy at San Francisco in May this year.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: HTTPS
Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo T5 Pro 5G With 9,020mAh Battery Arrives in India at This Price
  2. Oppo F33 5G Launches in India With These Specifications
  3. Oppo F33 Pro 5G Arrives in India With a 7,000mAh Battery at This Price
  4. Redmi A7 Pro 5G Goes on Sale in India: See Price, Features and Offers
  5. Motorola Edge 70 Pro Might Launch in India With This MediaTek Chip
  6. OnePlus Pad Lineup Set to Expand as Company Teases Launch of New Model
  7. These Samsung Galaxy S25 Models Just Received a Price Cut in India
  1. Vivo T5 Pro 5G Launched in India With 9,020mAh Battery, 50-Megapixel Rear Camera: Price, Specifications
  2. Samsung Galaxy S25 Ultra, Galaxy S25 FE and Galaxy S25 Get Price Cuts in India
  3. Oppo F33 5G Launched in India With Dimensity 6360 Max Chip, 7,000mAh Battery: Price, Specifications
  4. Bitcoin Price Consolidates Near $74,100 Following Pullback From Recent Rally
  5. Oppo F33 Pro 5G Launched in India With 7,000mAh Battery, 50-Megapixel Rear Camera: Price, Specifications
  6. Microsoft Surface PC Prices Raised as Memory Costs Rise; Flagship Devices Hit the Hardest
  7. Google App for Windows Rolls Out With AI Mode, System-Wide Search and Lens Features
  8. Redmi A7 Pro 5G With 6,300mAh Battery and 6.9-Inch Display Goes on Sale in India: Price, Offers
  9. Bloodborne Animated Film Adaptation in the Works at Sony
  10. DJI Osmo Pocket 4 Design Renders Leaked Ahead of Launch With 1-Inch Sensor, 4K 240fps Support
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.