Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
c0r0n3r
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
c0r0n3r
2mo ago
Which TLS/cryptography analyzer is right for you?
2.
▲
by
c0r0n3r
2y ago
Exploiting the computationally expensive nature of the Diffie-Hellman key exchange protocol an attacker can perform a denial-of-service (DoS) attack by sending arbitrary numbers as public keys to a target server forcing it to generate its p
3.
▲
by
c0r0n3r
2y ago
Conclusion "The DHEat attack remains viable against most SSH installations, as default settings are inadequate at deflecting it. Very little bandwidth is needed to cause a dramatic effect on targets, including those with a high degree
4.
▲
An Analysis of the DHEat DoS Against SSH in Cloud Environments
(positronsecurity.com)
2 points
by
c0r0n3r
2y ago
|
1 comments
5.
▲
D(HE)at: A Practical DoS Attack on the Finite Field Diffie–Hellman Key Exchange
(ieeexplore.ieee.org)
37 points
by
c0r0n3r
3y ago
|
13 comments
6.
▲
CryptoLyzer 0.12 –= SSLyze and testssl.sh and SSH-audit and Mozilla observatory
(cryptolyzer.readthedocs.io)
3 points
by
c0r0n3r
3y ago
|
0 comments
7.
▲
Server TLS settings analyzer CryptoLyzer with OpenVPN support has released
(gitlab.com)
1 points
by
c0r0n3r
3y ago
|
0 comments
8.
▲
CryptoLyzer 0.8.5 with browser (Chromium, Firefox, Opera) compatibility checker
(gitlab.com)
1 points
by
c0r0n3r
3y ago
|
0 comments
9.
▲
by
c0r0n3r
4y ago
We factorize a 48-bit integer using 10 trapped-ion qubits on a Quantinuum’s quantum computer. This result outperforms the recent achievement by B. Yan et al., arXiv:2212.12372 (2022), increasing the success probability by a factor of 6 with
10.
▲
Factorization (DCQF) of a 48-bit integer using 10 trapped-ion qubits
(arxiv.org)
1 points
by
c0r0n3r
4y ago
|
1 comments
11.
▲
Chinese researchers: RSA is breakable. Others: Do not panic
(helpnetsecurity.com)
1 points
by
c0r0n3r
4y ago
|
1 comments
12.
▲
by
c0r0n3r
4y ago
Chinese researchers claim that there is an existing algorithm that, even with today's quantum computers, makes it possible to break the RSA algorithm. At the same time, there are doubts about the reliability of the publication. However
13.
▲
OpenSSL: How to Configure LS Groups to Be Resistant to the DHEat Attack
(openssl.org)
1 points
by
c0r0n3r
4y ago
|
1 comments
14.
▲
by
c0r0n3r
4y ago
... The CVE-2002-20001 (a.k.a DHEat attack) vulnerability inherent to the support of the Diffie-Hellman (DH) and Elliptic Curve Diffie-Hellman (ECDH) key exchanges in TLS and other protocols provides a way for an attacker to cause high CPU
15.
▲
by
c0r0n3r
4y ago
You can also use CryptoLyzer[1] to audit your TLS (not just HTTPS, but SMTP, IMAP, ...) and SSH servers if you do not want to use SaaS solutions. There are another tools (open source and SaaS) on OWASP Transport Layer Protection Cheat Sheet
16.
▲
by
c0r0n3r
4y ago
The right URL is: https://dheatattack.com
17.
▲
DoS attack against Diffie-Hellman protocol
(dheat-attack.com)
2 points
by
c0r0n3r
4y ago
|
2 comments
18.
▲
by
c0r0n3r
4y ago
Who is affected? Websites, mail servers, and other Transport Layer Security (TLS) dependent services that support Diffie-Hellman key exchange using ephemeral keys (DHE cipher suites) are at risk of the DHEat attack. Services using other cry
19.
▲
DoS attack against Diffie-Hellman protocol
(dheat-attack.com)
21 points
by
c0r0n3r
4y ago
|
8 comments
20.
▲
by
c0r0n3r
4y ago
Who is affected? Websites, mail servers, and other Transport Layer Security (TLS) dependent services that support Diffie-Hellman key exchange using ephemeral keys (DHE cipher suites) are at risk of the DHEat attack. Services using other cry
21.
▲
by
c0r0n3r
4y ago
All the revocation checking mechanism have their pitfalls. It is a so complex issue. CRL has a very important benefit, namely it can be prefetched and can be updated regularly which is important in the case a firewall solution for instance.
22.
▲
How would Zero Trust prevent a Log4Shell attack?
(balasys.eu)
1 points
by
c0r0n3r
5y ago
|
0 comments
23.
▲
Modern Techniques to Prevent Malware Instead of Detecting It
(balasys.hu)
3 points
by
c0r0n3r
5y ago
|
0 comments
24.
▲
Another free CA as an alternative to Let's Encrypt
(scotthelme.co.uk)
736 points
by
c0r0n3r
6y ago
|
160 comments
25.
▲
Using the RNC Schema to Validate BIMI SVG Images
(bimigroup.org)
1 points
by
c0r0n3r
6y ago
|
0 comments
26.
▲
Why Do Certificate Revocation Checking Mechanisms Never Work?
(medium.com)
3 points
by
c0r0n3r
6y ago
|
0 comments
27.
▲
DNSSEC explained: Why you might want to implement it on your domain
(csoonline.com)
19 points
by
c0r0n3r
6y ago
|
14 comments
28.
▲
Minority Report on Let’s Encrypt CAA Rechecking
(dev.to)
1 points
by
c0r0n3r
6y ago
|
0 comments
29.
▲
CryptoLyzer 0.3.0: RDP support for TLS checkers, JA3 tag generation/decoding
(gitlab.com)
1 points
by
c0r0n3r
6y ago
|
0 comments
30.
▲
CRLite: Finally a Fix for Broken Revocation?
(scotthelme.co.uk)
1 points
by
c0r0n3r
7y ago
|
0 comments
More ›