Mike BelsheãSPDYã®å§ç¸®æ¹å¼ã¨æ»æãã¼ã«CRIMEã®ä»¶ã
2012.9.14 ietf-http-wgã¸ã®ãã¹ã
SPDY compression and CRIME attack from Mike Belshe on 2012-09-14 ([email protected] from July to September 2012)
- 2011å¹´ã«SSL/TSLã®èå¼±æ§ãçªããæ»æãã¼ã«ããªãªã¼ã¹ããJuliano Rizzoã¨Thai Duongã®ã³ã³ã
- ã»ãã·ã§ã³ãã¤ã¸ã£ãã¯ãã¼ã«BEAST
- TLS1.0/SSL3.0ã§æ¡ç¨ããã¦ãAESã使ã£ãcipher suiteã®èå¼±æ§ãçªã
- BEASTãªãªã¼ã¹ã®åé¿ãTLS1.2ã¸ã®ã¢ããã°ã¬ã¼ããcipher suiteã¯RC4ã¸ç§»è¡ããªã©ãªã©
- Rizzoã¨Duongã®ã³ã³ããæ°ä½ãã¼ã«CRIMEããªãªã¼ã¹
- Buenos Aireséå¬äºå®ã®Ekoparty security conferenceã§ãæ«é²ç®äºå®
- SSL/TSLå ¨ã¦ã®ver.ã«å¯¾ãã¦æå¹ãªæ»æææ³ãSPDYãå½ç¶æå¹ã«
- ãªãã·ã§ã³ã®å§ç¸®ããªã³ã«ãã¦ãSSLéä¿¡ã¨SPDYéä¿¡ã対象ã«ãªã
- Rizzoã¨Duongã¯youtubeã«ãã¢åç»UPãã¦ã
- CRIME vs startups - YouTube
- ãgithubãdropboxããããªé¢¨ã«ã»ãã·ã§ã³ãã¤ã¸ã£ãã¯ã§ãã¾ãããã¨ãã£ã¦ã
- github/dropboxå´ã®å¯¾å¿ï¼ï¼ãµã¼ãã¼å´ã§SSLå§ç¸®ããªãã«ããï¼å¾ã«åç»ã¯å ¬éããã¦ã
以ä¸æãèªãã å 容
- CRIMEã®ä»¶
- ssl - CRIME - How to beat the BEAST successor? - IT Security
- ã»ãã¥ãªãã£çstackoverflowï¼ã¨ããæãã®ãµã¤ãã®ã¹ã¬ãã
- åºåã£ã¦ãæ å ±ããææ³ãæ¨å®ãã¦ãã£ã¦ãããåããé¢ç½ã
- å§ç¸®ã»æå·åãããblobã®ä¸èº«ã¯å½ç¶ããããªãããblobã®é·ãã¯ææ¡ã§ãã
- RC4使ã£ã¦ãã°blogã®ç²åº¦ãããããããã¼ã§ããCookie: secret=0ãã¨ãããCookie: secret=1ãã¨ãä»è¾¼ãã§ãã£ã¦ãå§ç¸®çã®å¤åãè¦ã¦ããã°ãæ£è§£ãããã
- ãCookie: secret=ããã¹ã¿ã¼ãã«å¾åãï¼æåãã¤æ¨å®ãã¦ãã£ã¦ãCookie: secret=7xc89f+94/waããçªãæ¢ããææ³ã解説ãã¦ã
- ssl - CRIME - How to beat the BEAST successor? - IT Security
- ã¨ããç¶æ³ãè¸ã¾ãã¦ãspdyã®ä¸ã®äººã¨ãã¦mikeã¯æçãªãµããªã¼ãMLã«ãã¹ããã¦ã
- Fx/Chromeã¯ãããé©ç¨æ¸
- ææ°çã使ãã¦ã¼ã¶ã¯èå¼±æ§ãæ°ã«ããªãã§ä½¿ãã
- Fx/Chromeã¸ã®ãããã®é£ç¹
- SPDYãããã®å§ç¸®çãä½ä¸ãã¦ãã¾ã£ã
- å³å¯ãªããã©ã¼ãã³ã¹ã®æ¯è¼ã¯ãã£ã¦ãªãã
- http/2.0ã§ã¯ç¾è¡ã®spdyã¨ã¯ç°ãªãå§ç¸®ã©ã¤ãã©ãªã使ã£ã¦ããããã
- ã¨ã¯ããéçºã³ãã¥ããã£ã«ã¯å½±é¿ããã»ã©ãªã
- åã ããå§ç¸®ã©ã¤ãã©ãªã®å¤æ´ã¯è²ã ãªçç±ã§è¦æããã¦ã話ãªã®ã§
- ä»åã®åé¡ããã£ããã¨
- cookieã®ãããªã»ã³ã·ãã£ããªãã¼ã¿ã«ä½¿ãå§ç¸®æ¹å¼ã¨ãã¯ã¨ãªã¼æååã®ãããªã¦ã¼ã¶ã®ã³ã³ãã¼ã«ç®çã§ä½¿ããã¼ã¿ã®å§ç¸®æ¹å¼ãåãã§ããæ¡ä»¶ã§æå¹ãªæ»æ
- ãã®æ»æææ³ã使ãã¨SSLéä¿¡ã使ã£ã¦ã¦ãã¯ããã¼ã®ä¸èº«ããªãã¼ã¹ã»ã¨ã³ã¸ãã¢ãªã³ã°ã§ãã¦ãã¾ã
- æ»æè ãã¯ãªã¢ãã¹ãè¦ä»¶ã¯ï¼ã¤
- ã¿ã¼ã²ããã®ãã±ãããèªããã¨ãã§ãããã¨
- æ»æã®ä»è¾¼ã¿ã®ããã«ãã¿ã¼ã²ãããæ»æè ãç¨æãããµã¤ãã¸èªå°ã§ãããã¨
- 次æå§ç¸®æ¹å¼ã«ã¤ãã¦ã¯CRIME以åããã¨ã³ã¸ãã¢ãã¡ãåãçµãã§ã
- ä»åã®CRIMEã«ããæ»æãå¹ããªããã®ããã
- ä¸ä¾ã¨ãã¦Robert Peonã®å®è£
- å½¼ã®å®è£ ã¯SPDY/4ã¸æè¼ãç®æãã次æå§ç¸®æ¹å¼
- Robertã®ä»äºã¯CRIMEã¨ã¯ç¬ç«ãã¦é²ãããããã®
- Robertã«ããå®è£
ã¯ãªãªã¼ã¹ã§ããã¨ããã¾ã§éçºãé²ãã§ãªãããè²ã
ã¨åªãã¦ã
-
- spdy/3ãããå§ç¸®ã¬ãã«é¢ã§åä¸
- CPUæ¶è²»ãããä½ãï¼ã¤ã¾ãé«éã«ãªãï¼
- ã¡ã¢ãªæ¶è²»ã軽æ¸
- CRIMEã®æ»æãå¹ããªã
-