Over 13M HTTPS websites and email services using the TLS protocol vulnerable to new decryption attack, including over 97K of the top 1M most popular sites
More than 13 million HTTPS websites imperiled by new decryption attack — Low-cost DROWN attack decrypts data in hours, works against TLS e-mail servers, too.
Context & Ripple Effects
DROWN is the latest entry in a now-familiar genre of TLS protocol attacks that reuse old cryptographic weaknesses against modern connections. It follows Logjam's downgrade attack on tens of thousands of web and mail servers and the FREAK exploit that hit Android and iOS apps — both built on legacy export-era cipher support that was supposed to be dead.
What makes DROWN notable is scale and cost: decryption in hours at low cost across more than 13 million HTTPS sites and TLS email servers, including over 97K of the top 1M most popular sites. The related coverage shows the same pattern repeating — from NTP attacks that defeat HTTPS to app-level eavesdropping bugs — each one eroding what the green padlock actually guarantees.
First-order effects
- Operators of the 13 million affected HTTPS sites and TLS email servers face an immediate patch-or-expose decision: disable vulnerable legacy protocol support or leave traffic decryptable by anyone willing to spend a few hours of compute.
Second-order effects
- Email is the quieter exposure: mail servers negotiating TLS opportunistically stay vulnerable even when their web properties are patched, pushing administrators to harden SMTP encryption separately from their websites.
- Browser vendors and certificate authorities, already burned by Logjam and FREAK response cycles, face renewed pressure to force deprecation of legacy protocol versions rather than waiting for per-attack patches.
Third-order effects
- If the Logjam-FREAK-DROWN sequence holds, the industry's structural answer is aggressive retirement of old TLS versions and ciphers by default — shrinking the attack surface but making any residual legacy support a high-value target for the next attack.
- Each protocol-level break feeds the trust problem documented later in the related coverage, where exploitable TLS flaws persist on popular sites while browsers still show the reassuring padlock — pushing security expectations toward validation beyond the certificate icon.
The trend: TLS is being forced through a cycle of protocol-level breaks — Logjam, FREAK, now DROWN — that accelerates deprecation of legacy cryptography and shifts trust away from the padlock alone.