flâneur — a map of the web's best reading

BREACH - Wikipedia

en.wikipedia.org · 979 words · saved by 1 readers

BREACH (a backronym: Browser Reconnaissance and Exfiltration via Adaptive Compression of Hypertext) is a security vulnerability against HTTPS when using HTTP compression. BREACH is built based on the CRIME security exploit. BREACH was announced at the August 2013 Black Hat conference by security researchers Angelo Prado, Neal Harris and Yoel Gluck. The idea had been discussed in community before the announcement.[1] While the CRIME attack was presented as a general attack that could work effectively against a large number of protocols, only exploits against SPDY request compression and TLS compression were demonstrated and largely mitigated in browsers and servers. The CRIME exploits against HTTP compression has not been mitigated at all, even though the authors of CRIME have warned that this vulnerability might be even more widespread than SPDY and TLS compression combined. BREACH is an instance of the CRIME attack against HTTP compression—the use of gzip or DEFLATE data compression a

BREACH - Wikipedia Jump to content From Wikipedia, the free encyclopedia Security vulnerability against HTTPS For other uses, see Breach (disambiguation) . The official logo BREACH (a backronym : Browser Reconnaissance and Exfiltration via Adaptive Compression of Hypertext ) is a security vulnerability against HTTPS when using HTTP compression . BREACH is built based on the CRIME security exploit . BREACH was announced at the August 2013 Black Hat USA conference by security researchers Angelo Prado, Neal Harris and Yoel Gluck. Details [ edit ] While the CRIME attack was presented as a general

Explore this link on the map →

saved by

related reading