Repository logo

Infoscience

  • English
  • French
Log In
Logo EPFL, École polytechnique fédérale de Lausanne

Infoscience

  • English
  • French
Log In
  1. Home
  2. Academic and Research Output
  3. Conferences, Workshops, Symposiums, and Seminars
  4. Password interception in a SSL/TLS channel
 
conference paper

Password interception in a SSL/TLS channel

Canvel, Brice
•
Hiltgen, Alain
•
Vaudenay, Serge  
Show more
2003
The 23rd Annual International Cryptology Conference, CRYPTO '03
The 23rd Annual International Cryptology Conference, CRYPTO '03

Simple password authentication is often used e.g. from an e-mail software application to a remote IMAP server. This is frequently done in a protected peer-to-peer tunnel, e.g. by SSL/TLS. At Eurocrypt'02, Vaudenay (2002) presented vulnerabilities in padding schemes used for block ciphers in CBC mode. He used a side channel, namely error information in the padding verification. This attack was not possible against SSL/TLS due to both unavailability of the side channel (errors are encrypted) and premature abortion of the session in case of errors. In this paper we extend the attack and optimize it. We show it is actually applicable against latest and most popular implementations of SSL/TLS (at the time this paper was written) for password interception. We demonstrate that a password for an IMAP account can be intercepted when the attacker is not too far from the server in less than an hour in a typical setting. We conclude that these versions of the SSL/TLS implementations are not secure when used with block ciphers in CBC mode and propose ways to strengthen them. We also propose to update the standard protocol

  • Files
  • Details
  • Metrics
Type
conference paper
DOI
10.1007/978-3-540-45146-4_34
Author(s)
Canvel, Brice
Hiltgen, Alain
Vaudenay, Serge  
Vuagnoux, Martin  
Date Issued

2003

Published in
The 23rd Annual International Cryptology Conference, CRYPTO '03
Series title/Series vol.

Lecture Notes in Computer Science; 2729

Start page

583

End page

599

Editorial or Peer reviewed

REVIEWED

Written at

EPFL

EPFL units
LASEC  
Event nameEvent place
The 23rd Annual International Cryptology Conference, CRYPTO '03

Santa Barbara, CA, USA

Available on Infoscience
January 18, 2007
Use this identifier to reference this record
https://infoscience.epfl.ch/handle/20.500.14299/239692
Logo EPFL, École polytechnique fédérale de Lausanne
  • Contact
  • infoscience@epfl.ch

  • Follow us on Facebook
  • Follow us on Instagram
  • Follow us on LinkedIn
  • Follow us on X
  • Follow us on Youtube
AccessibilityLegal noticePrivacy policyCookie settingsEnd User AgreementGet helpFeedback

Infoscience is a service managed and provided by the Library and IT Services of EPFL. © EPFL, tous droits réservés