HTTPS isn’t always as secure as it seems
In analysis of the web’s top 10,000 HTTPS sites—as ranked by Amazon-owned analytics company Alexa—the researchers found that 5.5 percent had potentially exploitable TLS vulnerabilities. Riccardo Focardi, Ca’ Foscari University
The researchers say that beyond specific assessments of how many sites have TLS vulnerabilities, a crucial concept in this project has to do with the fundamental interconnectedness of the web and how small TLS flaws on one page have potential ramifications for many others. So the 5.5 percent of the top 10,000 sites that have flaws actually comes from 292 of the top 10,000 sites that have direct TLS vulnerabilities and 5,282 related sites that, through their own TLS bugs, create potential exposures for the main 10,000.
Source: www.wired.com