logo

Researchers: Hole In TLS Encryption Could Expose Secure Web Sessions

ID: f954c992-5753-59c0-bd58-979ac9dd5950

STIX ID: report--f954c992-5753-59c0-bd58-979ac9dd5950

Feed Name: Security Ledger

Threat Score
30/100

Date Published: 2013-02-04

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

Researchers at Royal Holloway, University of London disclosed a flaw in the TLS specification that can be exploited with timing-based attacks to recover complete blocks of TLS-encrypted plaintext. The paper describes proof-of-concept attacks that rely on detecting small differences in decryption timing and may require a very large number of TLS sessions or local network access, though more efficient variants can be possible in specific conditions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.