Crack in Internet's foundation of trust allows HTTPS session hijacking
Attack dubbed CRIME breaks crypto used to prevent snooping of sensitive data. — Researchers have identified a security weakness that allows them hijack web browser sessions even when they're protected by the HTTPS encryption …
Context & Ripple Effects
The CRIME disclosure lands a year after The Register ran a point-by-point catalog of SSL's structural weaknesses, and it converts that critique into a working attack: researchers demonstrated a method that defeats the crypto meant to keep sensitive data private and lets them hijack browser sessions even over HTTPS. Coverage was modest beyond Ars Technica — TechSpot picked the story up twice — so this is a specialist-audience story rather than a mass-market breach alert.
What makes CRIME notable within that arc is its class: rather than a certificate-authority failure or a single buggy implementation, it targets the TLS protocol machinery itself, which means every browser vendor, TLS library maintainer, and site operator shares exposure simultaneously.
First-order effects
- Browser makers and TLS library maintainers face immediate pressure to disable or rework the affected protocol feature, since any user whose traffic an attacker can observe is exposed to session hijacking.
- Website operators relying on HTTPS to protect logins and session cookies must reassess their server configurations, because the encryption they depend on no longer guarantees confidentiality against this technique.
Second-order effects
- Security teams at major sites will harden configurations ahead of vendor fixes, shifting operational cost from protocol designers to every downstream operator.
- The demonstration invites further research into side channels against TLS, raising scrutiny of other optional protocol features that trade performance for attack surface.
Third-order effects
- If protocol-level attacks keep surfacing, HTTPS risks a standing patch-and-hardening cycle in which 'encrypted' no longer means 'secure by default,' pressuring standards bodies toward more conservative protocol design.
- Enterprises and consumers may increasingly treat transport encryption as necessary but insufficient, accelerating demand for layered defenses beyond TLS.
The trend: SSL/TLS is settling into a cycle of recurring protocol-level flaw disclosures, where each confirmed attack forces coordinated patches across browsers, libraries, and servers and steadily erodes the assumption that HTTPS alone secures a session.