/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Crack in Internet's foundation of trust allows HTTPS session hijacking

Attack dubbed CRIME breaks crypto used to prevent snooping of sensitive data.  —  Researchers have identified a security weakness that allows them hijack web browser sessions even when they're protected by the HTTPS encryption …

Ars Technica Dan Goodin

Context & Ripple Effects

The CRIME disclosure lands a year after The Register ran a point-by-point catalog of SSL's structural weaknesses, and it converts that critique into a working attack: researchers demonstrated a method that defeats the crypto meant to keep sensitive data private and lets them hijack browser sessions even over HTTPS. Coverage was modest beyond Ars Technica — TechSpot picked the story up twice — so this is a specialist-audience story rather than a mass-market breach alert.

What makes CRIME notable within that arc is its class: rather than a certificate-authority failure or a single buggy implementation, it targets the TLS protocol machinery itself, which means every browser vendor, TLS library maintainer, and site operator shares exposure simultaneously.

First-order effects

  • Browser makers and TLS library maintainers face immediate pressure to disable or rework the affected protocol feature, since any user whose traffic an attacker can observe is exposed to session hijacking.
  • Website operators relying on HTTPS to protect logins and session cookies must reassess their server configurations, because the encryption they depend on no longer guarantees confidentiality against this technique.

Second-order effects

  • Security teams at major sites will harden configurations ahead of vendor fixes, shifting operational cost from protocol designers to every downstream operator.
  • The demonstration invites further research into side channels against TLS, raising scrutiny of other optional protocol features that trade performance for attack surface.

Third-order effects

  • If protocol-level attacks keep surfacing, HTTPS risks a standing patch-and-hardening cycle in which 'encrypted' no longer means 'secure by default,' pressuring standards bodies toward more conservative protocol design.
  • Enterprises and consumers may increasingly treat transport encryption as necessary but insufficient, accelerating demand for layered defenses beyond TLS.

The trend: SSL/TLS is settling into a cycle of recurring protocol-level flaw disclosures, where each confirmed attack forces coordinated patches across browsers, libraries, and servers and steadily erodes the assumption that HTTPS alone secures a session.