Collected research
HTTPS Bicycle Attack
Because stream-oriented TLS cipher suites such as GCM leak exact plaintext length, a passive eavesdropper can subtract the known, highly redundant parts of an HTTP request from the observed ciphertext size and deduce the length of a secret such as a password or cookie. The same length arithmetic narrows encrypted GPS coordinates to a map region and encrypted IPv4 addresses to a range.
Record
- Researcher
- Guido Vranken
- Published by
- guidovranken.files.wordpress.com
- Format
- Whitepaper
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Guido Vranken, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .