Loading…
25th USENIX Security Symposium has ended
Back To Schedule
Monday, August 8 • 11:00am - 11:30am
Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

We investigate nonce reuse issues with the GCM block cipher mode as used in TLS and focus in particular on AES-GCM, the most widely deployed variant. With an Internet-wide scan we identified 184 HTTPS servers repeating nonces, which fully breaks the authenticity of the connections. Affected servers include large corporations, financial institutions, and a credit card company. We present a proof of concept of our attack allowing to violate the authenticity of affected HTTPS connections which in turn can be utilized to inject seemingly valid content into encrypted sessions. Furthermore, we discovered over 70,000 HTTPS servers using random nonces, which puts them at risk of nonce reuse, in the unlikely case that large amounts of data are sent via the same session.



Speakers
HB

Hanno Böck

Writer, Freelance
PJ

Philipp Jovanovic

École polytechnique fédérale de Lausanne (EPFL)
avatar for Juraj Somorovsky

Juraj Somorovsky

Security Consultant, Ruhr-University Bochum
Juraj Somorovsky finished his PhD in the area of XML Security in 2013. In his thesis „On the Insecurity of XML Security“ he analyzes various attacks on Web Services and presents practical countermeasures against these attacks, which were applied in XML Security specifications... Read More →


Monday August 8, 2016 11:00am - 11:30am PDT
Texas Ballroom 1

Attendees (4)