| Publisher | Ecole Polytechnique Federale de Lausanne | ||
|---|---|---|---|
| Format | 162.2KB PDF | Date added | 01 Jan 2009 |
| Topics | Security Management, SSL - TLS | ||
| Downloads | 4 | ||
Simple password authentication is often used e.g. from an email software application to a remote IMAP server. This is frequently done in a protected peer-to-peer tunnel, e.g. by SSL/TLS. At Eurocrypt'02, Vaudenay presented vulnerabilities in padding schemes used for block ciphers in CBC mode. He used a side channel, namely error information in the padding verification. This attack was not possible against SSL/TLS due to both unavailability of the side channel (errors are encrypted) and premature abortion of the session in case of errors. This paper extends the attack and optimizes it. The paper shows it is actually applicable against latest and most popular implementations of SSL/TLS (at the time this paper was written) for password interception.
Related white papers
Activate Today!Realize ROI with Intel® vPro Technology and Microsoft System Configuration Manager
Join the team from the Intel vPro Expert Center for an informative Webcast on the ROI savings and activation process for PCs with Intel® vPro™ technology and Microsoft System Configuration...
Animated Demo of vPro Systems
This animated demo shows how vPro offers security and manageability on the chip.
Tube Lines reaps rewards of upgrading to Intel®Core™2 processor with vPro™technology
Tube Lines has a 30-year Public Private Partnership (PPP) contract with London Underground. It is responsible for the maintenance and upgrade of the infrastructure on the Jubilee, Northern and Piccadilly...
Video Case Study: Verizon UK
This video case study looks at how Chris Maylor, head of architecture services at Verizon UK, went about implementing vPro.
Webinar: Activate Today! Realize ROI with Intel® vPro Technology and Symantec Altiris
Join the team from the Intel vPro Expert Center for an informative Webcast on the ROI savings and activation process for PCs with Intel® vPro™ technology and Symantec Altiris. This...
vPro Expert Center Wiki, all you need to know about vPro and activation of vPro systems
Learn about vPro basics from this wiki. It contains info on what vPro is, as well as links to activation documentation.
vPro ROI Calculator
A free to use Intel PC Total Cost of Ownership Estimator



