由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
PDA版 - FREAK RSA weak key attack
相关主题
一到关键时刻就看出来DotNet架构的网站不行了推荐硬件VPN?
office2016的Outlook被Gmail认为是less secure APPNSA避免再爆丑闻,停止了加密软件Truecrypt的开发 (转载)
为何gmail收不了office 365 mail?如何加密云盘上的重要敏感文件?
来个学术贴具体分析一下heartbleed的原理.国内的网络真便宜
nokia 手机怎么收HOTMAIL华为mate9怎么添加yahoo信箱?
Android 安全: Poor SSL Implementations Leave Many Android Apps Vulnerable老中在dropbox里都放啥?
大家讨论了半天gmail收到钓鱼邮件和网站大家怎么把它玩坏
我觉得应该开题讨论反隐私暴露的技巧Win 8.1 Device Encryption is enabled by default
相关话题的讨论汇总
话题: rsa话题: export话题: weaker话题: keys话题: encryption
进入PDA版参与讨论
1 (共1页)
s*****m
发帖数: 13092
1
http://www.livehacking.com/2015/03/04/freak/
FREAK (or ‘Factoring attack on RSA-EXPORT Keys’) is a newly disclosed
vulnerability that can force browsers into using weaker encryption keys.
Once the connection is using weaker keys then the traffic can be cracked
relatively quickly. This then exposes all the information that was being
sent over the secure connection.
The vulnerability stems directly from an old U.S. government policy that
made it illegal to export strong encryption and required that weaker “
export-grade” products be shipped to customers in other countries. These
export restrictions were lifted in the late 1990s, but the weaker encryption
got built-in into widely used software, some of which made its way back
into USA.
...
It also looks like Android’s web browser and Apple’s Safari browser are
vulnerable. According to Matt Green, “A group of cryptographers at INRIA,
Microsoft Research and IMDEA have discovered some serious vulnerabilities in
OpenSSL clients (e.g., Android) and Apple TLS/SSL clients (e.g., Safari)
that allow a ‘man in the middle attacker’ to downgrade connections from ‘
strong’ RSA to ‘export-grade’ RSA.”
1 (共1页)
进入PDA版参与讨论
相关主题
Win 8.1 Device Encryption is enabled by defaultnokia 手机怎么收HOTMAIL
安卓root了就不能encrypt device了?Android 安全: Poor SSL Implementations Leave Many Android Apps Vulnerable
android的factory reset到底指什么。。。大家讨论了半天gmail
有人整过android tablet encryption 吗?我觉得应该开题讨论反隐私暴露的技巧
一到关键时刻就看出来DotNet架构的网站不行了推荐硬件VPN?
office2016的Outlook被Gmail认为是less secure APPNSA避免再爆丑闻,停止了加密软件Truecrypt的开发 (转载)
为何gmail收不了office 365 mail?如何加密云盘上的重要敏感文件?
来个学术贴具体分析一下heartbleed的原理.国内的网络真便宜
相关话题的讨论汇总
话题: rsa话题: export话题: weaker话题: keys话题: encryption