A serious attack against ciphertext secrets buried inside HTTPS responses has prompted an advisory from Homeland Security.
The BREACH attack is an offshoot of CRIME, which was thought dead and buried after it was disclosed in September. Released at last week’s Black Hat USA 2013, BREACH enables an attacker to read encrypted messages over the Web by injecting plaintext into an HTTPS request and measuring compression changes.
http://threatpost.com/breach-compression-attack-steals-https-secrets-in-under-30-seconds/101579
The BREACH attack is an offshoot of CRIME, which was thought dead and buried after it was disclosed in September. Released at last week’s Black Hat USA 2013, BREACH enables an attacker to read encrypted messages over the Web by injecting plaintext into an HTTPS request and measuring compression changes.
http://threatpost.com/breach-compression-attack-steals-https-secrets-in-under-30-seconds/101579