Collected research
Truncating TLS Connections to Violate Beliefs in Web Applications
TLS truncation lets an attacker cut off the tail of a response so browser and server end up disagreeing about what completed. The authors turned that desynchronisation into working attacks: casting votes on behalf of honest voters in the Helios e-voting system, taking full control of Microsoft Live accounts, and gaining temporary access to Google accounts.
Record
- Researcher
- Ben Smyth and Alfredo Pironti
- Published by
- usenix.org
- Topic
- Crypto
In the archive
Related sources
- Truncating TLS connections to steal Hotmail accounts
- Truncating TLS connections to access GMail accounts
Tags
This page is the archive's own catalogue record. The research is the work of Ben Smyth and Alfredo Pironti, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .