Web Hack List

Collected research

Triple Handshakes and Cookie Cutters: Breaking and Fixing Authentication over TLS

A man-in-the-middle can synchronise the master secret across two TLS connections by chaining RSA or Diffie-Hellman key exchange, session resumption and renegotiation, so the client's later authentication is redirected to the attacker's server. This breaks tls-unique channel binding, PEAP, SASL and channel-bound cookies, and related truncation tricks cut HTTPS headers to strip cookie flags.

Record

Researcher
Karthikeyan Bhargavan, Antoine Delignat-Lavaud, Cédric Fournet, Alfredo Pironti and Pierre-Yves Strub
Published by
ieee-security.org
Format
Whitepaper
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Karthikeyan Bhargavan, Antoine Delignat-Lavaud, Cédric Fournet, Alfredo Pironti and Pierre-Yves Strub, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .