3 ms·
TLS connections that implement forward secrecy are not vulnerable to this type of attack. According to SSL Labs, about half of all sites now support forward sec
by bendykstra 11y ago
TLS connections that implement forward secrecy are not vulnerable to this type of attack. According to SSL Labs, about half of all sites now support forward secrecy.
https://www.trustworthyinternet.org/ssl-pulse/ https://www.trustworthyinternet.org/ssl-pulse/
- gcr 11y agoOnly if it's implemented correctly.
- sibrahim 11y agoThis may be true for now, but if/when scalable quantum computing arrives, the recorded key exchange can be used to recover the session key (much easier than attacking AES itself). If you need confidentiality in the face of quantum adversaries, you'll need post quantum crypto but this is still a fairly young area of research.
- traff 11y agoIt's possible to decrypt the exact URL you're browsing for a large majority of websites with very high probability, even with forward secrecy. There is an undergraduate project that does this for wikipedia pages (it's easy because of all the unique resources loaded for each page). Search for papers on https traffic analysis, for example: http://arxiv.org/abs/1403.0297 http://arxiv.org/abs/1403.0297