Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End
How broken is TLS?
A tale of BEAST, CRIME, Lucky Thirteen and Heartbleed Hanno B¨
- ck, https://hboeck.de
2014-04-19
1 / 44
How broken is TLS? A tale of BEAST, CRIME, Lucky Thirteen and - - PowerPoint PPT Presentation
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End How broken is TLS? A tale of BEAST, CRIME, Lucky Thirteen and Heartbleed Hanno B ock, https://hboeck.de 2014-04-19 1 / 44 Introduction Software CAs Introduction
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End
1 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Introduction Motivation History of SSL / TLS Overview
2 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Introduction Motivation History of SSL / TLS Overview
3 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Introduction Motivation History of SSL / TLS Overview
4 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Introduction Motivation History of SSL / TLS Overview
5 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Heartbleed Software Featurebloat C
6 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Heartbleed Software Featurebloat C
7 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Heartbleed Software Featurebloat C
8 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Heartbleed Software Featurebloat C
9 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Certificate Authorities 2011 CA disaster Revocation Revocation that costs money Fixing CAs
10 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Certificate Authorities 2011 CA disaster Revocation Revocation that costs money Fixing CAs
11 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Certificate Authorities 2011 CA disaster Revocation Revocation that costs money Fixing CAs
12 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Certificate Authorities 2011 CA disaster Revocation Revocation that costs money Fixing CAs
13 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Certificate Authorities 2011 CA disaster Revocation Revocation that costs money Fixing CAs
14 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Algorithms Signaturen
15 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Algorithms Signaturen
16 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Algorithms BEAST CBC, MAC, Padding From the TLS 1.2 standard Lucky Thirteen CBC RC4 RC4 or CBC
17 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Algorithms BEAST CBC, MAC, Padding From the TLS 1.2 standard Lucky Thirteen CBC RC4 RC4 or CBC
18 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Algorithms BEAST CBC, MAC, Padding From the TLS 1.2 standard Lucky Thirteen CBC RC4 RC4 or CBC
19 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Algorithms BEAST CBC, MAC, Padding From the TLS 1.2 standard Lucky Thirteen CBC RC4 RC4 or CBC
20 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Algorithms BEAST CBC, MAC, Padding From the TLS 1.2 standard Lucky Thirteen CBC RC4 RC4 or CBC
21 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Algorithms BEAST CBC, MAC, Padding From the TLS 1.2 standard Lucky Thirteen CBC RC4 RC4 or CBC
22 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Algorithms BEAST CBC, MAC, Padding From the TLS 1.2 standard Lucky Thirteen CBC RC4 RC4 or CBC
23 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Algorithms BEAST CBC, MAC, Padding From the TLS 1.2 standard Lucky Thirteen CBC RC4 RC4 or CBC
24 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Forward Secrecy Elliptic Curves NIST Curves Curve25519 Compression
25 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Forward Secrecy Elliptic Curves NIST Curves Curve25519 Compression
26 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Forward Secrecy Elliptic Curves NIST Curves Curve25519 Compression
27 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Forward Secrecy Elliptic Curves NIST Curves Curve25519 Compression
28 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Forward Secrecy Elliptic Curves NIST Curves Curve25519 Compression
29 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Downgrades F5 / BIG-IP Frankencerts Dual EC DRBG Triple Handshake SSL Stripping / HSTS ASN.1 Quantum Computers Tipps for server admins
30 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Downgrades F5 / BIG-IP Frankencerts Dual EC DRBG Triple Handshake SSL Stripping / HSTS ASN.1 Quantum Computers Tipps for server admins
31 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Downgrades F5 / BIG-IP Frankencerts Dual EC DRBG Triple Handshake SSL Stripping / HSTS ASN.1 Quantum Computers Tipps for server admins
32 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Downgrades F5 / BIG-IP Frankencerts Dual EC DRBG Triple Handshake SSL Stripping / HSTS ASN.1 Quantum Computers Tipps for server admins
33 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Downgrades F5 / BIG-IP Frankencerts Dual EC DRBG Triple Handshake SSL Stripping / HSTS ASN.1 Quantum Computers Tipps for server admins
34 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Downgrades F5 / BIG-IP Frankencerts Dual EC DRBG Triple Handshake SSL Stripping / HSTS ASN.1 Quantum Computers Tipps for server admins
35 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Downgrades F5 / BIG-IP Frankencerts Dual EC DRBG Triple Handshake SSL Stripping / HSTS ASN.1 Quantum Computers Tipps for server admins
36 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Downgrades F5 / BIG-IP Frankencerts Dual EC DRBG Triple Handshake SSL Stripping / HSTS ASN.1 Quantum Computers Tipps for server admins
37 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Downgrades F5 / BIG-IP Frankencerts Dual EC DRBG Triple Handshake SSL Stripping / HSTS ASN.1 Quantum Computers Tipps for server admins
38 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Two Possible Conclusions Read and Learn Sources Sources Sources Final words
39 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Two Possible Conclusions Read and Learn Sources Sources Sources Final words
40 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Two Possible Conclusions Read and Learn Sources Sources Sources Final words
41 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Two Possible Conclusions Read and Learn Sources Sources Sources Final words
42 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Two Possible Conclusions Read and Learn Sources Sources Sources Final words
43 / 44
Introduction Software CAs X.509 Symmetric encryption TLS misc Misc End Two Possible Conclusions Read and Learn Sources Sources Sources Final words
44 / 44