Zurück   Free To Advertise Forum >Community Center >General Discussion

General Discussion

Talk about anything from politics to t.v. shows, kids, internet news ....etc This is the place to also blow off some steam from your normal day activities. NO Affiliate Links!


If you register for free, you will be able to post threads, vote on polls and lots more. If you have problems with the registration or logging in, please contact the administrator.

Antwort
 
Themen-Optionen
  Side Channel Attacks in SSL Beitrag #1  
Alt 08-17-2010, 03:00 AM
rhody249 rhody249 ist offline
New Marketer
 
Registriert seit: Dec 2009
Beiträge: 95
Standard Side Channel Attacks in SSL

For those of you who may not have seen it there is a very good paper partially by Microsoft Research and partially by Indiana.edu called Side-Channel Leaks in Web Applications: a Reality Today, a Challenge Tomorrow. Initially it really upset me off that this paper was written, not because it’s not excellent, but because it’s partially what I was going to be speaking about at Blackhat. Alas… they came out with it first, and frankly, I think they did a much better job at slicing and dicing with the math. So once being upset by being beaten to the punch had worn off Josh Sokol and I had to change the presentation that we’ll be doing at Blackhat, and we’ll only be glossing over this as a result. But please check it out, it must have taken quite a while to build up those abuse cases.

Anyway, the reason I originally started thinking about this was because of something from Bruce Schneier I read a decade or so ago (I believe it was in Applied Cryptography). It basically said that in certain crypto systems you could tell certain things about the people involved. For instance, if you had one user who sent an encrypted message to two users who then sent the same message to four users who then sent it to 8 and so on… you might be able to infer a chain of command (or, just as likely - a really funny/crude joke that no one wants their bosses to find out about).

But when you’re talking about HTML, you have a lot of things that sort of act as subordinates in the same way as a chain of command might. For instance, HTML can load JavaScript, CSS, Objects, etc… those can load more JavaScript, Images, Bindings, etc… All of that has a certain behavior in the browser, and in one way or another can be detected. So the trick is how do you detect it? The Indiana paper does a good job of enumerating some of those possibilities, but there are a lot of other tricks an attacker could use as a man in the middle to reduce the noise on the wire. That’s what the presentation is largely about. Anyway, check out the paper!
Mit Zitat antworten
Antwort

Zurück   Free To Advertise Forum >Community Center >General Discussion

Themen-Optionen


Similar threads to Side Channel Attacks in SSL
Thema Autor Forum Antworten Letzter Beitrag
Always got PANIC ATTACKS??? End Your Anxiety & Panic Attacks Naturally!!!!
Always got PANIC ATTACKS??? End Your Anxiety & Panic Attacks Naturally!!!!: Is Any Of This Experience Familiar To You? ...
lynx_girlus Products, Services & Offers 0 07-22-2009 05:44 AM
Go Daddy $12.99 SSL Sale!
Go Daddy $12.99 SSL Sale!: :rolleyes: GoDaddy.com hosting plans are ideal...
zaisan Business Opportunities 0 03-02-2009 01:59 PM
Go Daddy $12.99 SSL Sale!
Go Daddy $12.99 SSL Sale!: :)GoDaddy.com hosting plans are ideal for most...
zaisan Business Opportunities 0 02-18-2009 12:09 PM
Go Daddy $12.99 SSL Sale!
Go Daddy $12.99 SSL Sale!: GoDaddy.com hosting plans are ideal for most...
zaisan Income Opportunities 0 02-15-2009 11:18 AM
Go Daddy $14.99 SSL Sale!
Go Daddy $14.99 SSL Sale!: hosting, server, website, domain transfer,...
rissaasthon Products, Services & Offers 0 12-26-2008 12:35 PM

More threads of rhody249
Thema Datum Forum Antworten Letzter Beitrag
10 tips on how to increase your website traffic
10 tips on how to increase your website traffic: Hi friends, Here are the ten useful tips, ...
06-01-2010 General Discussion 2 12-28-2011 06:00 AM
Hidden movie in Windows XP
Hidden movie in Windows XP: Hi friends, Today I am going to share a very cool...
06-01-2010 General Discussion 0 06-01-2010 05:00 AM
Please do not laugh!
Please do not laugh!: In U.S. they invented a machine that catches...
06-01-2010 General Discussion 0 06-01-2010 02:49 AM
Switch from Google to Bing???
Switch from Google to Bing???: Bing has really stepped up their ad campaign, at...
06-01-2010 General Discussion 0 06-01-2010 02:39 AM
Which will be the hottest movie in 2010??
Which will be the hottest movie in 2010??: Hi friends I just wanna know that which Hollywood...
01-31-2010 General Discussion 0 01-31-2010 11:53 PM

Other threads in forum General Discussion
Thema Datum Autor Antworten Letzter Beitrag
Online home business opportunity
Online home business opportunity: Do you want to be rich and start your own Home...
11-29-2009 alahori355 0 11-29-2009 02:12 AM


Alle Zeitangaben in WEZ -4. Es ist jetzt 05:44 AM Uhr.


Powered by vBulletin® Version 3.8.7 (Deutsch)
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
2007-2008 Free To Advertise Forum
Sedo - Domains kaufen und verkaufen das Projekt freetoadvertise.biz steht zum Verkauf Besucherstatistiken von freetoadvertise.biz etracker® Web-Controlling statt Logfile-Analyse
You are viewing Side Channel Attacks in SSL

SEO by vBSEO 3.2.0