The OpenNET Project / Index page

[ новости /+++ | форум | теги | ]



"Новая техника атаки на SSL, которой подвержены 33% HTTPS-сайтов"
Версия для распечатки Пред. тема | След. тема
Форум Разговоры, обсуждение новостей
Исходное сообщение [ Отслеживать ]
Присылайте удачные настройки в раздел примеров файлов конфигурации на WIKI.opennet.ru.
. "Новая техника атаки на SSL/TLS, которой подвержены 33% HTTPS..." +2 +/
Сообщение от Аноним (-), 01-Мрт-16, 21:28 
TLS 1.3 на подходе, обратной совместимости и даунгрейда не будет.

The best way to promote the use of secure connections, HTTPS is to improve the current protocols to be as fast and secure as possible. One of the protocols that are currently being revised is the protocol TLS, Transport Layer Security, successor of SSL protocol, in order to improve the security of this protocol at the same time that it considerably reduces the waiting time in the negotiations to reduce the maximum waiting times.

With the aim of improving the performance and security of all secure connections, so as to speed up the processes of TLS negotiation, is reviewing the protocol for the launch of a new version of the same which is intended to be the definitive reason for that all, or at least most of the website servers connected to the Internet to establish secure connections between client-server, ensuring the security and privacy of users.

The current version of TLS is 1.2, which, when complete, the corresponding revisions will be the TLSv1.3. Among the main differences between both versions are to be noted:
* It removes the support of the GMT time in favor of UTC.
* It has changed the name of the function KeyExchange to KeyShare.
* Added a new function "HelloRetryRequest" to refuse to unauthorized customers.
* It has been revised negotiation Handshake in order to provide mode 1-RTT.
* You have deleted the groups DUS custom.
* It eliminates the possibility of compression.
* It has eliminated the possibility of an exchange of RSA keys and DH static.
* Removed support for encryption systems that are not AEAD.

Of all of the above characteristics, the most important in terms of performance is the review of the negotiation 1-RTT. The new TLS 1.3 is going to streamline significantly the processes of negotiation to establish secure connections with you so that the process can work without problem on servers "little powerful", and reduce as well the waiting times and the appearance of "lag" that show some sites.

Ответить | Правка | Наверх | Cообщить модератору

Оглавление
Новая техника атаки на SSL, которой подвержены 33% HTTPS-сайтов, opennews, 01-Мрт-16, 21:07  [смотреть все]
Форумы | Темы | Пред. тема | След. тема



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру