3 ms·
Colour me stupid, but is there something to prevent inserting indeterminate padding while sending headers? e.g. imagine a request like GET / HTTP/1.0 X
by forgotusername 14y ago
Colour me stupid, but is there something to prevent inserting indeterminate padding while sending headers? e.g. imagine a request like
GET / HTTP/1.0
X-Pad: GET / HTTP/aaaaaaa
Where X-Pad randomly repeats previous bytes, and perhaps 0..8 bytes of random/repeating variable-length data. By randomizing the effectiveness of the compression, surely this attack can be generally prevented by the browser?
You could argue that given enough samples the noise could be filtered and the attack still remains, but the same could be said the same for many successful patches over the years (TCP sequence number randomization, Kaminsky's DNS issue, etc.), and the number of samples required would be pretty infeasible.
- riannucci 14y agoI'm fairly certain this could be defeated with a little differential cryptanalysis. Similar approaches to defeating side-channel attacks on smart card power usage have been tried and defeated :/
- StavrosK 14y agoIf it's random, you can just get enough samples and remove the noise. It'd have to be padding to a given number of bytes, but that probably has a vulnerability too.
- caf 14y agoThere's no point - you're better off just disabling TLS compression and doing whatever compression of the body-only at the HTTP level.