Researchers: Hole In TLS Encryption Could Expose Secure Web Sessions
ID: f954c992-5753-59c0-bd58-979ac9dd5950
STIX ID: report--f954c992-5753-59c0-bd58-979ac9dd5950
Feed Name: Security Ledger
Threat Score
Researchers at Royal Holloway, University of London disclosed a flaw in the TLS specification that can be exploited with timing-based attacks to recover complete blocks of TLS-encrypted plaintext. The paper describes proof-of-concept attacks that rely on detecting small differences in decryption timing and may require a very large number of TLS sessions or local network access, though more efficient variants can be possible in specific conditions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
