Website Security & Threat Management
Understanding the prevalence of web traffic interception

Understanding the prevalence of web traffic interception

9/12/2017 · Guest Author, Nick Sullivan

What this post added

This post details a study on the prevalence of HTTPS interception, finding that 4-10% of encrypted web traffic is intercepted. It explains the mechanisms of local and remote interception, how interceptors forge certificates by adding their own root CA to trust stores, and the security implications of weakened encryption. The study used TLS fingerprinting to identify interceptors and found Windows to be intercepted more often than macOS, with mobile OSes being least intercepted. Firefox showed a different distribution with mobile carrier providers being a significant source of interception due to its separate certificate store. Interceptions are attributed to security improvement efforts (antivirus, firewalls) and malicious activities (malware).

Read the original post ↗