Collected research
HEIST: HTTP Encrypted Information can be Stolen Through TCP-Windows
Browser timing APIs expose when a response arrives relative to TCP window boundaries, letting a malicious page measure the exact byte length of any cross-origin HTTPS response. Because TLS does not hide length, compression oracles like CRIME and BREACH become exploitable from JavaScript alone with no man-in-the-middle position, and HTTP/2 makes the attack stronger still.
Record
- Researcher
- Mathy Vanhoef and Tom Van Goethem
- Published by
- blackhat.com
- Format
- Whitepaper
- Topic
- HTTP
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Mathy Vanhoef and Tom Van Goethem, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .