• Home
  • Search
  • Why didn't we spot that? [Practical Security
  • Cite Icon5
  • https://doi.org/10.1109/mic.2010.21Copy DOI Icon

Why didn't we spot that? [Practical Security

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

The Secure Sockets Layer (SSL) protocol and its standards-track successor, the Transport Layer Security (TLS) protocol, were developed more than a decade ago and have generally withstood scrutiny in that the protocols themselves haven't been found to have security flaws. Marsh Ray and Steve Dispensa discovered a design flaw in the TLS protocol that affects all versions of the protocol up to and including the current version.Whereas the vulnerability itself is serious, it need not affect many deployments once administrators apply suitable patches to disable renegotiation, leaving TLS sufficiently secure in most cases because exploiting the vulnerability requires the attacker to be an active man-in-themiddle, redirecting traffic between victims (for example, a browser and a Web server). However, because security problems only ever get worse, a change to the protocol is required. The vulnerability is an interesting attack in itself, but perhaps more interesting is the question, why didn't we see this earlier? In this article, the author explore this question but, unfortunately, can't answer it. Hopefully, simply asking the question might prompt developers to re-examine assumptions they've forgotten they've even made.

Similar Papers
  • Research Article

A Comparative Study of SSL and TLS Protocols for Securing Network Communication in Modern Web Applications

  • Jan 01, 2025
  • International Journal of Scientific Research and Management (IJSRM)
  • Emmanuel Danjuma Onoja +2
  • Book Chapter
  • Citations1

Chapter 59 - Virtual Private Networks

  • Jan 01, 2025
  • Computer and Information Security Handbook
  • Jim Harmening
  • Conference Article
  • Citations2

.NET Security: IPSec vs. SSL

  • Mar 26, 2004
  • J Raissi
  • Research Article
  • Citations22

ME-TLS: Middlebox-Enhanced TLS for Internet-of-Things Devices

  • Nov 22, 2019
  • IEEE Internet of Things Journal
  • Jie Li +4
  • Conference Article

SSL transmission delay optimization in multi-core processor based on network path delay prediction

  • Oct 01, 2017
  • Zhengzhi Tang +3
  • Book Chapter

Chapter 10 - Java Secure Sockets Layer

  • Jan 01, 2002
  • Developing Web Services with Java APIs for XML Using WSDP
  • Jerry Foster +3
  • Conference Article
  • Citations4

Analyzing Spatial Differences in the TLS Security of Delegated Web Services

  • May 24, 2021
  • Joonhee Lee +4
  • Conference Article
  • Citations12

Secure channel establishment in disadvantaged networks : Optimizing TLS using intercepting proxies

  • Oct 01, 2010
  • Joseph A Cooley +2
  • Conference Article
  • Citations20

Modified SET protocol for mobile payment: An empirical analysis

  • Oct 01, 2010
  • Sabrina M Shedid +1
  • Research Article

Penerapan Sectigo Positive Ssl Pada Pengamanan Web Site

  • Apr 04, 2024
  • JURNAL MEDIA INFOTAMA
  • Khairullah Khairullah +3
  • Conference Article
  • Citations1

Internet of Things Security: We're Walking on Eggshells!

  • Jan 01, 2016
  • Aref Meddeb
  • Conference Article
  • Citations8

Safe configuration of TLS connections

  • Oct 01, 2013
  • Michael Atighetchi +5
  • Conference Article
  • Citations100

Studying TLS Usage in Android Apps

  • Nov 28, 2017
  • Abbas Razaghpanah +5
  • Journal Title

Jurnal Jaringan Komputer dan Keamanan

  • Sep 16, 2023
  • Jurnal Jaringan Komputer dan Keamanan
  • Research Article
  • Citations4

Towards Validation of TLS 1.3 Formal Model and Vulnerabilities in Intel’s RA-TLS Protocol

  • Jan 01, 2024
  • IEEE Access
  • Muhammad Usama Sardar +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.