Collected research
On the Practical (In-)Security of 64-bit Block Ciphers (SWEET32)
SWEET32: Birthday attacks on 64-bit block ciphers in TLS and OpenVPN
Ciphers with 64-bit blocks such as Triple-DES and Blowfish hit the birthday bound after only about 32 GB under one key, so colliding CBC ciphertext blocks leak the XOR of two plaintexts. An attacker running JavaScript in the victim's browser and watching the wire can recover an HTTP cookie or Basic Auth token from a long-lived TLS or OpenVPN connection.
Record
- Document
- SWEET32: Birthday attacks on 64-bit block ciphers in TLS and OpenVPN
- Researcher
- Karthikeyan Bhargavan and Gaëtan Leurent
- Published by
- sweet32.info
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Karthikeyan Bhargavan and Gaëtan Leurent, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .