7. A few attacks
While a security protocol aims to counter certain threats to user data (these are known as first-order threats), its mechanisms themselves open the door to new attack possibilities, known as second-order threats. As a result, a protocol can only be considered valid with regard to these two types of attack. Having seen how TLS counters first-order attacks on transactions, the completeness of the analysis now requires us to look at second-order attacks aimed directly at TLS.
Attacks on TLS, as on all protocols in general, fall into three categories. Firstly, there are implementation flaws due to misinterpretation by the developer, defects in the design of an application or poor consideration of security as a whole. Vulnerabilities of this type are linked to a particular application: they appear regularly as implementation flaws are discovered, and are usually promptly...
You do not have access to this resource.
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed?
Log in!
Ongoing reading
A few attacks