SSL: Intercepted today, decrypted tomorrow

SSL: Intercepted today, decrypted tomorrow

The United States is far from the only government wishing to monitor encrypted internet traffic: Saudi Arabia has asked for help decrypting SSL traffic, China has been accused of performing a MITM attack against SSL-only GitHub, and Iran has been …
See all stories on this topic »

Lane-shift on I-75 causes traffic back-up – WNEM TV 5

By Tom Plahutnik, Web Editor/Producer – email. This map highlights the exact locations of the back-up. SAGINAW COUNTY, MI (WNEM) -. TV5 has learned road construction on southbound I-75 near the southbound I-675 ramp has snarled traffic.
See all stories on this topic »

Social Media May Soon Drive More Traffic to Your Website Than …

A new report suggests internet users in the U.S. are looking to sites like Facebook and Twitter to find what they're looking for online.
See all stories on this topic »

Popular Questions

What does “SSL: intercepted today, decrypted tomorrow” mean?

The phrase describes a harvest-now, decrypt-later attack. An attacker can copy encrypted traffic today and store it until advances in cryptanalysis or access to future decryption capabilities make the data readable. Sensitive information such as login details, customer records, private messages, and business plans may remain valuable long after it was captured.

Why is SSL traffic vulnerable to the “intercepted today, decrypted tomorrow” threat?

SSL and TLS protect data while it travels, but encryption does not guarantee that captured traffic will stay confidential forever. If an attacker records encrypted sessions and later obtains a private key, exploits a weakness, or uses more powerful computing methods, some past traffic may become accessible. Organizations should therefore protect both current sessions and the secrets that could expose archived communications.

How can a business reduce the risk of SSL traffic being decrypted in the future?

Use current TLS versions, disable obsolete protocols and weak cipher suites, and keep web servers, applications, and security devices patched. Protect private keys with strong access controls, secure key storage, and regular rotation where practical. Businesses should also inventory long-lived sensitive data and evaluate encryption methods that can be upgraded as stronger cryptographic standards become available.

What should network marketers do about SSL data that could be decrypted tomorrow?

Network marketers should treat customer, distributor, payment, and campaign information as sensitive even when it is transmitted over HTTPS. Confirm that websites, forms, email systems, and third-party tools use properly configured TLS and avoid sending confidential data through unprotected channels. Limit data retention, remove old records that are no longer needed, and ask vendors how they protect archived traffic and encryption keys.

Scroll to Top