CRIME Attack Uses Compression Ratio of TLS Requests as Side Channel to Hijack Secure Sessions (threatpost)
CRIME Attack Uses Compression Ratio of TLS Requests as Side Channel to Hijack Secure Sessions (threatpost)
Posted Sep 13, 2012 18:48 UTC (Thu) by butlerm (subscriber, #13312)Parent article: CRIME Attack Uses Compression Ratio of TLS Requests as Side Channel to Hijack Secure Sessions (threatpost)
How does the attacker get the size of the compressed data without packet sniffing on the client? And presumably the only way to packet sniff on the client is already to have made a root level compromise.
But if you have a root level compromise, you could presumably capture the actual keystrokes or even read the decrypted cookie out of the browser memory. No?
