Postcards from the Post-HTTP World: Amplification of HTTPS Vulnerabilities in the Web Ecosystem
Stefano Calzavara, Riccardo Focardi, Matús Nemec, Alvise Rabitti, Marco Squarcina
Abstract
HTTPS aims at securing communication over the Web by providing a cryptographic protection layer that ensures the confidentiality and integrity of communication and enables client/server authentication. However, HTTPS is based on the SSL/TLS protocol suites that have been shown to be vulnerable to various attacks in the years. This has required fixes and mitigations both in the servers and in the browsers, producing a complicated mixture of protocol versions and implementations in the wild, which makes it unclear which attacks are still effective on the modern Web and what is their import on web application security. In this paper, we present the first systematic quantitative evaluation of web application insecurity due to cryptographic vulnerabilities. We specify attack conditions against TLS using attack trees and we crawl the Alexa Top 10k to assess the import of these issues on page integrity, authentication credentials and web tracking. Our results show that the security of a consistent number of websites is severely harmed by cryptographic weaknesses that, in many cases, are due to external or related-domain hosts. This empirically, yet systematically demonstrates how a relatively limited number of exploitable HTTPS vulnerabilities are amplified by the complexity of the web ecosystem.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4d7b8bce-9ad2-4d4e-af15-2c743f8395e7Cited by top-tier papers5
- The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization FlawsKostas Drakonakis, Sotiris Ioannidis, Jason PolakisCCS 2020 · 56 citations
- Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On DeploymentsMohammad Ghasemisharif, Chris Kanich, Jason PolakisS&P 2022 · 25 citations
- Meddling Middlemen: Empirical Analysis of the Risks of Data-Saving Mobile BrowsersBrian Kondracki, Assel Aliyeva, Manuel Egele, Jason Polakis et al.S&P 2020 · 13 citations
- Understanding and Detecting Abused Image Hosting Modules as Malicious ServicesGeng Hong, Mengying Wu, Pei Chen, Xiaojing Liao et al.CCS 2023 · 3 citations
- You Get What You Sample: Evaluating Sampling Strategies for Web Security MeasurementsXuenan Zhang, Yuqing Yang, Giancarlo PellegrinoCCS 2026
Builds on17
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- DROWN: Breaking TLS Using SSLv2Nimrod Aviram, Sebastian Schinzel, Juraj Somorovsky, Nadia Heninger et al.USENIX Security 2016 · 192 citations
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer et al.USENIX Security 2017 · 177 citations
- The Security Impact of HTTPS InterceptionZakir Durumeric, Zane Ma, Drew Springall, Richard Barnes et al.NDSS 2017 · 161 citations
- Systematic Fuzzing and Testing of TLS LibrariesJuraj SomorovskyCCS 2016 · 136 citations
Related papers
- Scalable Scanning and Automatic Classification of TLS Padding Oracle VulnerabilitiesRobert Merget, Juraj Somorovsky, Nimrod Aviram, Craig Young et al.USENIX Security 2019 · 27 citations
- ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS AuthenticationMarcus Brinkmann, Christian Dresen, Robert Merget, Damian Poddebniak et al.USENIX Security 2021 · 20 citations
- Talking with Familiar Strangers: An Empirical Study on HTTPS Context Confusion AttacksMingming Zhang, Xiaofeng Zheng, Kaiwen Shen, Ziqiao Kong et al.CCS 2020 · 15 citations
- Opossum Attack: Application Layer Desynchronization using Opportunistic TLSRobert Merget, Nurullah Erinola, Marcel Maehren, Lukas Knittel et al.USENIX Security 2026
- The Cracked Cookie Jar: HTTP Cookie Hijacking and the Exposure of Private InformationSuphannee Sivakorn, Iasonas Polakis, Angelos D. KeromytisS&P 2016 · 86 citations
