Top 10 winner
Lucky 13 Attack
Lucky Thirteen: Breaking the TLS and DTLS Record Protocols
TLS and DTLS CBC decryption runs measurably faster when a record carries at least two bytes of valid padding, because the 13-byte MAC header aligns hash compression blocks differently. Timing TLS error messages on a LAN and averaging out jitter recovers a plaintext block in about 2^23 sessions, fewer with base64 or BEAST-style tricks; DTLS falls in a single session.
Record
- Document
- Lucky Thirteen: Breaking the TLS and DTLS Record Protocols
- Researcher
- Nadhem AlFardan and Kenny Paterson
- Published by
- isg.rhul.ac.uk
- Topic
- Other
In the archive
Related sources
- Lucky Thirteen Whitepaper
- DTLS timing amplification Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of Nadhem AlFardan and Kenny Paterson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .