Imperfect forward secrecy.
We investigate the security of Diffie-Hellman key exchange as used in popular Internet protocols and find it to be less secure than widely believed. First, we present Logjam, a novel flaw in TLS that lets a man-in-the-middle downgrade connections to "export-grade" Diffie-Hellman. To carry out this a...
| Publicado en: | Communications of the ACM Vol. 62; no. 1; pp. 106 - 115 |
|---|---|
| Autores principales: | , , , , , , , , , , , , , |
| Formato: | Artículo |
| Publicado: |
Association for Computing Machinery
Jan2019
|
| Materias: | |
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=134657151&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 134657151 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 00010782 ACM jtl: Communications of the ACM issn: 00010782 maglogo: N pubinfo: dt: Jan2019 vid: 62 iid: 1 pid: 68 pub: Association for Computing Machinery artinfo: ui: 134657151 10.1145/3292035 ppf: 106 ppct: 9 formats: tig: atl: Imperfect forward secrecy. aug: au: Adrian, David Bhargavan, Karthikeyan Durumeric, Zakir Gaudry, Pierrick Green, Matthew Halderman, J. Alex Heninger, Nadia Springall, Drew Thomé, Emmanuel Valenta, Luke VanderSloot, Benjamin Wustrow, Eric Zanella-Béguelin, Santiago Zimmermann, Paul su: Computer network protocols Public key cryptography Cryptography Cryptosystems Data encryption Computer network security Virtual private networks sug: subj: Computer network protocols Public key cryptography Cryptography Cryptosystems Data encryption Computer network security Virtual private networks ab: We investigate the security of Diffie-Hellman key exchange as used in popular Internet protocols and find it to be less secure than widely believed. First, we present Logjam, a novel flaw in TLS that lets a man-in-the-middle downgrade connections to "export-grade" Diffie-Hellman. To carry out this attack, we implement the number field sieve discrete logarithm algorithm. After a week-long precomputation for a specified 512-bit group, we can compute arbitrary discrete logarithms in that group in about a minute. We find that 82% of vulnerable servers use a single 512-bit group, and that 8.4% of Alexa Top Million HTTPS sites are vulnerable to the attack. In response, major browsers have changed to reject short groups. We go on to consider Diffie-Hellman with 768- and 1024-bit groups. We estimate that even in the 1024-bit case, the computations are plausible given nation-state resources. A small number of fixed or standardized groups are used by millions of servers; performing precomputation for a single 1024-bit group would allow passive eavesdropping on 18% of popular HTTPS sites, and a second group would allow decryption of traffic to 66% of IPsec VPNs and 26% of SSH servers. A close reading of published NSA leaks shows that the agency's attacks on VPNs are consistent with having achieved such a break. We conclude that moving to stronger key exchange methods should be a priority for the Internet community. pubtype: Periodical doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2019 holdings: @attributes: islocal: N |
|---|