HEIST is a big DEAL — Medium

HEIST is a big DEAL Newly Discovered Exploit Should Trigger a Moratorium on Blocking Adblockers and a Retooling of AdChoices At this year’s BLACK HAT conference in Las Vegas, Belgian researchers Mathy Vanhoef and Tom Van Goethem demonstrated a newly discovered technique where JavaScript loaded by a third-party is able to circumvent the encryption of…

Read More

How the HTTPS-snooping, email addy and SSN-raiding HEIST JavaScript code works • The Register

Black Hat Malicious ads can potentially masquerade as people online and grab their personal information from HTTPS-protected websites, two boffins have shown. The technique is dubbed HEIST – HTTP Encrypted Information can be Stolen through TCP-Windows – and it was devised by Tom Van Goethem and Mathy Vanhoef, both PhD researchers at the University of…

Read More