4 ms·
It seems that this is an attack on the CBC-mode ciphers but doesn't change anything about the RC4 ciphers. RC4 is mentioned in passing as having weaknesses, bu
by omh 12y ago
It seems that this is an attack on the CBC-mode ciphers but doesn't change anything about the RC4 ciphers.
RC4 is mentioned in passing as having weaknesses, but is it actually broken? If we can't disable SSL3 completely would using only RC4 ciphers be an option?
- mzs 12y agoRC4 in TLS is pretty bad too: http://www.isg.rhul.ac.uk/tls/ http://www.isg.rhul.ac.uk/tls/ "Our second attack applies to TLS and can be carried out in a single connection or session (but tolerates multiple connections/sessions). It exploits certain double-byte biases in RC4 keystreams (the Fluhrer-McGrew biases). It targets plaintext bytes located at any position in the TLS plaintext stream. The number of encryptions needed to reliably recover a set of 16 consecutive targeted plaintext bytes is around 10 times 2^30, but already with only 6 times 2^30 sessions, these target bytes can be recovered with 50% reliability. Since this double-byte bias attack does not require the TLS Handshake Protocol to be rerun, it can in practice be more efficient than our single-byte bias attack." http://www.isg.rhul.ac.uk/tls/RC4biases.pdf http://www.isg.rhul.ac.uk/tls/RC4biases.pdf edit: I could not get star to show-up, so I just spelled it out as 'times.'
- omh 12y agoThat's the "worst" RC4 attack I'm aware of. But I'm not sure that it's quite at the level of a practical attack - certainly not as bad as POODLE.