4 ms·
It's been a while since I have worked in this space but the underlying protocol (AIS) is incredibly lacking in terms of security due to the nature of plain text
by afvictory 6y ago
It's been a while since I have worked in this space but the underlying protocol (AIS) is incredibly lacking in terms of security due to the nature of plain text transmission & lack of authentication. I'm not sure if these issues have been addressed but below is some great research from 2014 on the matter [1][2].
[1] https://www.blackhat.com/docs/asia-14/materials/Balduzzi/Asia-14-Balduzzi-AIS-Exposed-Understanding-Vulnerabilities-And-Attacks.pdf https://www.blackhat.com/docs/asia-14/materials/Balduzzi/Asi...
[2] https://www.youtube.com/watch?v=5rt9dzu3I7U https://www.youtube.com/watch?v=5rt9dzu3I7U
- kasperni 6y agoThe payload length for a single AIS slot is 168 bit. So there is really no room for any kind of security headers.