Playback: A TLS 1.3 Story

preview_player
Показать описание
This talk will describe the technical details regarding the TLS 1.3 0-RTT feature and its associated risks. It will include Proof of Concepts (PoC) showing real-world replay attacks against TLS 1.3 libraries and browsers. Finally, potential solutions or mitigation controls would be discussed that will help to prevent those attacks when deploying software using a library with TLS 1.3 support.

By Alejo Murillo + Alfonso Garcia Alguacil

Рекомендации по теме
Комментарии
Автор

Shouldn’t the attack in last demo fail because the server implemented single session enforcement?

annakh