3 ms·
No that is not all an attacker could know. TLS does not provide confidentiality of the number of bytes transmitted. So in your example an attacker would only ha
by spand 10y ago
No that is not all an attacker could know. TLS does not provide confidentiality of the number of bytes transmitted. So in your example an attacker would only have to crawl the public website and find the pages matching in size to the ones you have been browsing.
- cmdrfred 10y agoGood point I hadn't considered that.
- paulddraper 10y agoCookies, user-agent header, and keep-alives will make that very hard to figure out.
- rplst8 10y agoCouldn't this be thwarted by injecting random bytes into each page served to vary the file sizes?
- mi100hael 10y agoThere are web server modules that will append random-length comments to the end of a page's HTML in order to foil this kind of attack https://github.com/nulab/nginx-length-hiding-filter-module https://github.com/nulab/nginx-length-hiding-filter-module