Episode 19: Cross-Protocol Attacks on TLS with ALPACA!
Cryptography FM12 Jul 2021

Episode 19: Cross-Protocol Attacks on TLS with ALPACA!

TLS is an internet standard to secure the communication between servers and clients on the internet, for example that of web servers, FTP servers, and Email servers. This is possible because TLS was designed to be application layer independent, which allows its use in many diverse communication protocols.

ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. Attackers can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.

Links and papers discussed in the show:

Music composed by Toby Fox and performed by Sean Schafianski.

Special Guests: Marcus Brinkmann and Robert Merget.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(24)

Episode 24: CryptoHack's Collection of Cryptic Conundrums!

Episode 24: CryptoHack's Collection of Cryptic Conundrums!

For several years, CryptoHack has been a free platform for learning modern cryptography through fun and challenging programming puzzles. From toy ciphers to post-quantum cryptography, CryptoHack has a...

27 Feb 202349min

Episode 23: Psychic Signatures in Java!

Episode 23: Psychic Signatures in Java!

On April 19th 2022, Neil Madden disclosed a vulnerability in many popular Java runtimes and development kits. The vulnerability, dubbed "Psychic Signatures", lies in the cryptography for ECDSA signatu...

25 Jan 202353min

Episode 22: Three Lessons from Threema: Breaking a Secure Messenger!

Episode 22: Three Lessons from Threema: Breaking a Secure Messenger!

Threema is a Swiss encrypted messaging application. It has more than 10 million users and more than 7000 on-premise customers. Prominent users of Threema include the Swiss Government and the Swiss Arm...

16 Jan 202352min

Episode 21: Proving Fundamental Equivalencies in Isogeny Mathematics!

Episode 21: Proving Fundamental Equivalencies in Isogeny Mathematics!

Benjamin Wesolowski talks about his latest paper in which he mathematically proved that the two fundamental problems underlying isogeny-based cryptography are equivalent. Links and papers discussed i...

24 Aug 202146min

Episode 20: Cryptanalysis of GPRS: GEA-1 and GEA-2!

Episode 20: Cryptanalysis of GPRS: GEA-1 and GEA-2!

A team of cryptanalysits presents the first publicly available cryptanalytic attacks on the GEA-1 and GEA-2 algorithms. Instead of providing full 64-bit security, they show that the initial state of G...

20 Jul 202142min

Episode 18: Optimizing Cryptography for Microcontrollers!

Episode 18: Optimizing Cryptography for Microcontrollers!

Nadim talks with Peter Schwabe and Matthias Kannwischer about the considerations — both in terms of security and performance — when implementing cryptographic primitives for low-level and embedded pla...

23 Jun 202136min

Episode 17: Breaking Wi-Fi With Frame Attacks!

Episode 17: Breaking Wi-Fi With Frame Attacks!

Wi-Fi is a pretty central technology to our daily lives, whether at home or at the office. Given that so much sensitive data is regularly exchanged between Wi-Fi devices, a number of standards have be...

1 Jun 202135min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
aftenpodden-usa
forklart
popradet
fotballpodden-2
nokon-ma-ga
stopp-verden
rss-espen-lee-usensurert
rss-gukild-johaug
det-store-bildet
dine-penger-pengeradet
lydartikler-fra-aftenposten
hanna-de-heldige
rss-ness
aftenbla-bla
rss-dannet-uten-piano
chit-chat-med-helle
rss-penger-polser-og-politikk
e24-podden