FIESTA: an HTTPS side-channel party - Jose Selvi
249 views · Published 1 October 2018 · 42:12 · Indexed 29 September 2026
Channel: OWASP Foundation · 2018 · Science & Technology
OWASP AppSec EU 2018 Hacker Track - Day 2, talk 3 In the past few years, several attacks exploiting side-channel issues in TLS traffic have been launched with the aim of extracting information protected by HTTPS. CRIME, BREACH,, and TIME are all good examples of such attacks. But they are known, and most Internet sites have introduced countermeasures to protect against them. Unfortunately, this is not enough to protect sensitive online information. HTTPS traffic has other side-channels that could be exploited in a similar way, exposing private information. It this paper, we present a new tool, called FIESTA, that will help us test this kind of issues. In addition, we release a new side-channel not used before, affecting the most important technology companies in the Internet. Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP_Media_Project
More from this channel
-
35:56
HTML5 JS Security - maty siman
-
46:05
Next Generation Red Teaming - Robert Wood
-
17:39
detecting and defending against state actor surveillance: robert r
-
50:12
OWASP Global Webinar - OWASP HIVE Project - Welcome to the Grid
-
50:42
OWASP Global Webinar - Initiatives OWASP Projects
-
42:16
Alvaro Muoz - Automatic Detection of Inadequate Authorization Checks in Web Applications
-
40:10
Tin Zaw Scott Matsumoto - Threat Modeling A Brief History and the Unified Approach at Intuit
-
2:26:27
OWASP AppSecUSA 2014 - Breakers Track - Friday