3 ms·
BEAST and CRIME are both chosen-plaintext attacks. They don't rely on the improper MAC composition in TLS CBC. Lucky13 and POODLE are the chosen-ciphertext att
by sdevlin 11y ago
BEAST and CRIME are both chosen-plaintext attacks. They don't rely on the improper MAC composition in TLS CBC.
Lucky13 and POODLE are the chosen-ciphertext attacks.
EDIT: Some more details:
BEAST takes advantage of predictable IVs in SSLv3 and TLS 1.0. In these protocols, the IV for each new record is simply the last block of the previous record. An attacker monitoring traffic on the wire can use this predictability to build an encryption oracle and guess-and-check the contents of ciphertext blocks.
CRIME uses plaintext compression to its advantage. A message with longer common substrings will compress slightly better than one without, and this is reflected in the ciphertext length. An attacker can make adaptively chosen guesses at substrings included in the message to recover, e.g., session cookies.
- tptacek 11y agoD'oh. Sorry. It's release day here. POODLE is the best example, I think.
- sdevlin 11y agoIt happens. :) I agree, POODLE is a close analog.
- api 11y agoGreat takeaways from BEAST and CRIME. For BEAST, my takeaway was to never introduce a dependency into a cryptosystem of any kind without thinking very carefully about the implications-- and if in doubt, don't do it. I also took away "don't be creative" -- boring crypto is best. Generating random IVs from a CSPRNG is boring. Reusing the last block is interesting, but there be dragons. Crypto should be boring, straightforward, and directly based upon the current state of the art best practices without introducing anything that hasn't been subjected to rigorous analysis. Complexity equals bugs, etc. For CRIME the takeaway is the concise "never compress somethings secret together with something attacker-influenced." It means one must be careful in using compression together with encryption, and that if one is very highly paranoid it is probably best to leave compression out to err on the side of caution.
- tptacek 11y agoNit: chaining IVs was the norm, used in a bunch of protocols, until the mid-2000s. It's obvious why you'd want to do it (saves space, and, conceptually, the IV is the negative-oneth ciphertext block anyways).