Главная
Study mode:
on
1
Choosing a cipher
2
Block ciphers and Modes of operation
3
Birthday paradox
4
Security of modes of operation
5
Communication issues
6
Outline
7
Impact
8
Towards a practical attack
9
HTTP authentication tokens
10
Beastly Attack Scenario
11
3DES use in TLS (HTTPS)
12
HTTPS session length
13
Countermeasures
14
Comparison with RC4 attacks
15
Conclusion
Description:
Explore the practical insecurity of 64-bit block ciphers in this conference talk presented at CCS 2016. Delve into collision attacks on HTTP over TLS and OpenVPN, examining the vulnerabilities of block ciphers and modes of operation. Understand the birthday paradox and its implications for security. Analyze communication issues and the impact of these vulnerabilities. Learn about a practical attack scenario involving HTTP authentication tokens and the "Beastly Attack." Investigate the use of 3DES in TLS (HTTPS) and the significance of HTTPS session length. Discover potential countermeasures and compare these attacks with RC4 attacks. Gain valuable insights into the security challenges posed by 64-bit block ciphers and their implications for modern cryptographic protocols.

On the Practical - In-Security of 64-bit Block Ciphers - Collision Attacks on HTTP over TLS and OpenVPN

Association for Computing Machinery (ACM)
Add to list
0:00 / 0:00