oss-sec mailing list archives
Re: feedback requested regarding deprecation of TLS 1.0/1.1
From: Peter Gutmann <pgut001 () cs auckland ac nz>
Date: Fri, 9 Aug 2024 08:37:28 +0000
steffen <steffen () sdaoden eu> writes:
That is: whether "vulnerability" thus means to create a fake packet with identical MD-5 and SHA-1 hashes (it seems TLSv1.1 always uses both concurrently, at least for RSA) as the cryptographically verifiable one that ships with the packet. It seems to me this is hard stuff, especially for "the occasional attack".
It's not just hard, for TLS it's pretty much impossible. The collision attacks against SHA-1 have been chosen-prefix and very much offline which you can't do with TLS. Even then, it's only the handshake which uses SHA-1, the rest uses HMAC-SHA1 which, even for MD5, is still secure. Finally, TLS < 1.2 uses MD5+SHA1 in combination, which no-one has found an actual attack on yet. So in this case TLS 1.2 is actually weaker than TLS 1.1. There's also the issue I cover in: http://www.cs.auckland.ac.nz/~pgut001/pubs/bollocks.pdf which is really about quantum cryptanalysis but also covers other attack types. Peter.
Current thread:
- Re: feedback requested regarding deprecation of TLS 1.0/1.1, (continued)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Jeffrey Walton (Aug 07)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Dan Kegel (Aug 07)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Demi Marie Obenour (Aug 07)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 niekt0 (Aug 07)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Solar Designer (Aug 07)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Pat Gunn (Aug 07)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Steffen Nurpmeso (Aug 07)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Clemens Lang (Aug 08)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Steffen Nurpmeso (Aug 08)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 steffen (Aug 08)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Peter Gutmann (Aug 09)
- Re: collision confounders (was: feedback requested regarding deprecation of TLS 1.0/1.1) Jacob Bachmeyer (Aug 16)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Demi Marie Obenour (Aug 08)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Clemens Lang (Aug 08)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Jacob Bachmeyer (Aug 09)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Jens Timmerman (Aug 09)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Marco Moock (Aug 07)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Neil Horman (Aug 07)
