Reply to post: As a client, there is not much you can do.

How the HTTPS-snooping, email addy and SSN-raiding HEIST JavaScript code works

Tom 64
Coffee/keyboard

As a client, there is not much you can do.

But if you are a server op, simply turning off compression on your https connections mitigates this attack.

This has been a best practice for a while, but as you can imagine there a LOT of sites out there that don't do this, including your regular high-street banks.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon