3 ms·
I don't know why the authors didn't make a website for the SCISSOR attack (a.k.a the cookie cutter attack in the paper), which is way more practical and (imho)
by cryptbe 13y ago
I don't know why the authors didn't make a website for the SCISSOR attack (a.k.a the cookie cutter attack in the paper), which is way more practical and (imho) much cooler than this session resumption thing.
The idea of that attack is similar to what we did in CRIME, but applies to HTTP responses. Basically you inject enough data to split the response into two records and drop the second one. Some browsers would happily accept the truncated response, and change their state. As a result you could remove the Secure flag on the Set-Cookie header, and steal the cookies if the server or the client doesn't support HSTS.
- tptacek 13y agoIt is a neat attack, I agree. Do you have any idea which browsers are vulnerable to it? Technically, the protocol handles this case, by distinguishing between an authenticated connection close message and an RST?