New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

traffic analysis on TLS packets #162

Open
hannesm opened this Issue Jul 14, 2014 · 0 comments

Comments

1 participant
@hannesm
Member

hannesm commented Jul 14, 2014

(from http://tools.ietf.org/html/draft-pironti-tls-length-hiding-02):
When using CBC block ciphers, the TLS protocol provides means to frustrate attacks based on analysis of the length of exchanged messages, by adding extra pad to TLS records. However, the TLS specification does not define a length hiding method for applications that require it. In fact, current implementations of eager fragmentation strategies or random padding strategies have been showed to be ineffective against this kind of traffic analysis.

Solution: implement length hiding policy http://tools.ietf.org/html/draft-pironti-tls-length-hiding-02

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment