4 ms·
DoS attack against Diffie-Hellman protocol
- c0r0n3r 4y agoWho is affected? Websites, mail servers, and other Transport Layer Security (TLS) dependent services that support Diffie-Hellman key exchange using ephemeral keys (DHE cipher suites) are at risk of the DHEat attack. Services using other cryptographic protocols can also be affected. * Secure Shell (SSH) services support Diffie-Hellman key exchange methods. * Internet Protocol Security (IPsec) services offer DH groups. * OpenVPN servers support Diffie-Hellman key exchange in the control channel (DHE TLS ciphers).
- josephcsible 4y agoDHE has already been considered weak, with ECDHE as the recommended replacement, for a long time now, so I suspect that most systems operated by people who take security seriously already won't be vulnerable to this.
- meltyness 4y agoYour post corroborates SUSE[0] claims that ECDHE is not vulnerable to this. Default golang TLS server looks like it's got it's head on straight for this. [0] https://www.suse.com/support/kb/doc/?id=000020510 https://www.suse.com/support/kb/doc/?id=000020510
- jslaD 4y agoI’m getting a certificate error.
- LinuxBender 4y agoQualys is too [1] [1] - https://www.ssllabs.com/ssltest/analyze.html?d=dheat-attack.com https://www.ssllabs.com/ssltest/analyze.html?d=dheat-attack....
- justinludwig 4y agoLooks like the URL for this post should be this instead: https://dheatattack.com/ https://dheatattack.com/
- cft 4y agoThis is one year old (11/11/21), see date at the bottom: https://nvd.nist.gov/vuln/detail/CVE-2002-20001 https://nvd.nist.gov/vuln/detail/CVE-2002-20001
- CodesInChaos 4y agoI'm a bit confused what the attack is. Is it just that SSL handshakes are expensive for the server, while the client avoids the computational cost because it chooses a random public key instead of one for which it knows the private key? And why doesn't this also apply to plain RSA and ECDHE_RSA suites, which need to compute an expensive RSA private key operation, which should be similarly expensive as DH?