‘CRIME’ attack abuses SSL/TLS data compression feature to hijack HTTPS sessions

The 'CRIME' attack announced last week exploits the data compression scheme used by the TLS (Transport Layer Security) and SPDY protocols to decrypt user authentication cookies from HTTPS (HTTP Secure) traffic, one of the attack's creators confirmed Thursday.

read more

Read more: ‘CRIME’ attack abuses SSL/TLS data compression feature to hijack HTTPS sessions

Story added 14. September 2012, content source with full text you can find at link above.