Re: [TLS] NIST TLS recomendations (PKCS#1 encryption attacks)
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] NIST TLS recomendations (PKCS#1 encryption attacks)



On Tue, Nov 28, 2006 at 03:49:13PM +1300, Peter Gutmann wrote:

> Another thing that should really be mentioned in the text (which I've pointed
> out before) is that the requirement to continue makes for a marvellous DoS
> attack, just blindly send a string of TLS handshake packets with a garbage
> value for the RSA-encrypted data and the server has to go through the entire
> rest of the handshake.  In some situations (e.g. low-powered devices) this
> "defensive" measure may be an own-goal.

Is this relevant?  The adversary might just as well send valid
RSA-encrypted data (which is quite quickly done for e=65537) to keep
the server busy.  Even with invalid RSA-encrypted data, the server
already has spent considerable effort on RSA decryption when it can
finally check the padding -- so it's not as if servers could
effortlessly handle the DoD attack that you described without the
Bleichenbacher defense.

Bodo


_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.