以下斜め読んだ内容

pseudo translation of useful posts, book reviews, remarks,etc. twitter: feeddict

Mike Belshe「SPDYの圧縮方式と攻撃ツールCRIMEの件」

2012.9.14 ietf-http-wgへのポスト

SPDY compression and CRIME attack from Mike Belshe on 2012-09-14 (ietf-http-wg@w3.org from July to September 2012)



2011SSL/TSLJuliano RizzoThai Duong

BEAST

TLS1.0/SSL3.0AES使cipher suite

BEASTTLS1.2cipher suiteRC4


RizzoDuongCRIME

Buenos AiresEkoparty security conference

ekoparty Security Conference


SSL/TSLver.SPDY

SSLSPDY

RizzoDuongyoutubeUP

CRIME vs startups - YouTube

githubdropbox

github/dropboxSSL




CRIME

ssl - CRIME - How to beat the BEAST successor? - IT Security

stackoverflow



blobblob

RC4使blogCookie: secret=0Cookie: secret=1

Cookie: secret=1Cookie: secret=7xc89f+94/wa



spdymikeML

'CRIME' Attack Abuses SSL/TLS Data Compression Feature to Hijack HTTPS Sessions CIO.com


Fx/Chrome

使使


Fx/Chrome

SPDY




http/2.0spdy使







cookie使使

使SSL使

2






CRIME

CRIME

Robert Peon



SPDY-Specification/example_code at gh-pages · grmocg/SPDY-Specification


SPDY/4

RobertCRIME

Robert



spdy/3


CPU



CRIME