Re: Net security software exposed

From: Vlastimil Klima (vlastimil.klima@i.cz)
Date: 02/21/03


From: "Vlastimil Klima" <vlastimil.klima@i.cz>
Date: Fri, 21 Feb 2003 10:41:38 +0100


> Story from BBC NEWS:
> http://news.bbc.co.uk/go/pr/fr/-/2/hi/technology/2785145.stm

> This looks to be a valid, real-world attack on SSL/TLS. More details at:
http://lasecwww.epfl.ch/memo_ssl.shtml

Very nice attack, congratulations to the researchers!

BTW: You may see our comment sent to 'IETF Transport Layer Security WG' on
Jun 20, 2002 :-)

".... For instance, there still exists a risk of timing side channel
(unveiling whether it was padding or MAC, what failed,
especially for longer records)..... Hope that programmers will be aware of
these pitfalls.
Vlastimil Klima and Tomas Rosa.",

see http://www.imc.org/ietf-tls/mail-archive/msg03536.html

Vlastimil and Tom



Relevant Pages

  • Re: Borland Developer Studio 2006 rocks!
    ... > Leroy Casterline wrote: ... > Congratulations to both of you guys :-) ... BTW, I approached the choice of my second wife as an engineering project. ...
    (borland.public.delphi.non-technical)
  • Re: The Laguna Band Saw arrived
    ... Congratulations, finally! ... That motor is BIG ... ... when I see the lights dim over here today I'll know ... (BTW, you have more patience than me ... ...
    (rec.woodworking)
  • Re: [slrn] Tutorial of the Week :-)
    ... Congratulations. ... BTW, I saw that you link in you slrn tutorial ... to my ubuntu package. ... The slrn-0.9.9 subdirectory doesn't exist anymore ...
    (news.software.readers)
  • Re: 60 cm sidehop competition!
    ... It's been raining all day today:/ ... Anyways, congratulations:D Btw, did it have to be -over- a ledge? ...
    (rec.sport.unicycling)