Measuring the Security Harm of TLS Crypto Shortcuts
Measuring the Security Harm of TLS Crypto Shortcuts
复制标题
衡量 TLS 加密快捷方式的安全危害
DOI:
--
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
J. A. Halderman
中科院分区:
文献类型:
--
作者:
Drew Springall;Zakir Durumeric;J. A. Halderman
TLS has the potential to provide strong protection against network-based attackers and mass surveillance, but many implementations take security shortcuts in order to reduce the costs of cryptographic computations and network round trips. We report the results of a nine-week study that measures the use and security impact of these shortcuts for HTTPS sites among Alexa Top Million domains. We find widespread deployment of DHE and ECDHE private value reuse, TLS session resumption, and TLS session tickets. These practices greatly reduce the protection afforded by forward secrecy: connections to 38% of Top Million HTTPS sites are vulnerable to decryption if the server is compromised up to 24 hours later, and 10% up to 30 days later, regardless of the selected cipher suite. We also investigate the practice of TLS secrets and session state being shared across domains, finding that in some cases, the theft of a single secret value can compromise connections to tens of thousands of sites. These results suggest that site operators need to better understand the tradeoffs between optimizing TLS performance and providing strong security, particularly when faced with nation-state attackers with a history of aggressive, large-scale surveillance.