3 ms·
Theoretical attacks have a way of turning into weaponized exploits. For example, check out https://www.openssl.org/~bodo/tls-cbc.txt https://www.openssl.org/~b
by sdevlin 11y ago
Theoretical attacks have a way of turning into weaponized exploits.
For example, check out https://www.openssl.org/~bodo/tls-cbc.txt https://www.openssl.org/~bodo/tls-cbc.txt. This is a document published by Bodo Moeller in the early 2000s that details multiple theoretical weaknesses in the CBC mode used in TLS. Read it top to bottom and see how many practical attacks on TLS you can count.
- tptacek 11y agoThis one was turned into a further-weaponized attack, published in the author's masters thesis, which is in the bibliography for the paper. I don't know why this paper was published independently, as it's a building block for the other attack.
- psycocrypt 11y agoWhat other attack?
- detaro 11y agohttps://news.ycombinator.com/item?id=10713064 https://news.ycombinator.com/item?id=10713064