Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

TLS connections that implement forward secrecy are not vulnerable to this type of attack. According to SSL Labs, about half of all sites now support forward secrecy.

https://www.trustworthyinternet.org/ssl-pulse/



It's possible to decrypt the exact URL you're browsing for a large majority of websites with very high probability, even with forward secrecy. There is an undergraduate project that does this for wikipedia pages (it's easy because of all the unique resources loaded for each page). Search for papers on https traffic analysis, for example:

http://arxiv.org/abs/1403.0297


This may be true for now, but if/when scalable quantum computing arrives, the recorded key exchange can be used to recover the session key (much easier than attacking AES itself). If you need confidentiality in the face of quantum adversaries, you'll need post quantum crypto but this is still a fairly young area of research.


Only if it's implemented correctly.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: