4 ms·
Interesting. It looks like the page itself is encrypted with more standard crypto using AES [0], but the video itself is served from a connection using RC4 [1].
by timothya 12y ago
Interesting. It looks like the page itself is encrypted with more standard crypto using AES [0], but the video itself is served from a connection using RC4 [1].
As far as I can tell from this article [2], attacks on RC4 are only theoretical at this point, but it seems reasonable that they should upgrade the video serving domain to be consistent with the page itself (though maybe it's done for performance reasons - either encrypting a large video stream costs a lot of CPU time or decrypting it on the client is too slow or CPU intensive for watching video smoothly, so perhaps they are sticking with RC4 for a good reason). Still, as my old crypto prof said, "Attacks only get better over time. They never get worse."
[0]: http://i.imgur.com/OcpziFa.png http://i.imgur.com/OcpziFa.png
[1]: http://i.imgur.com/57T8bay.png http://i.imgur.com/57T8bay.png
[2]: https://community.qualys.com/blogs/securitylabs/2013/03/19/rc4-in-tls-is-broken-now-what https://community.qualys.com/blogs/securitylabs/2013/03/19/r...
- EthanHeilman 12y agoAttacks on RC4 are publically theoretical but people have come forward to say that the NSA[1], and likely other intelligence agencies, can break RC4 in real time. Given what we know about the theoretical attacks, this does not stretch the imagination. [1]: https://twitter.com/ioerror/status/398059565947699200 https://twitter.com/ioerror/status/398059565947699200
- tptacek 12y agoThe attacks are not "theoretical". They are in fact trivial to implement. What you mean to say here is that the attacks are difficult to launch in practice. That is true: while the code to attack RC4 is simple, the attack generates a huge amount of bandwidth.