Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks
Some tales about TLS
Hanno B¨
- ck
https://hboeck.de/
1 / 60
Some tales about TLS Hanno B ock https://hboeck.de/ 1 / 60 - - PowerPoint PPT Presentation
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Some tales about TLS Hanno B ock https://hboeck.de/ 1 / 60 Introduction Certificate Authorities Algorithms How broken is TLS? Attacks
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks
1 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks How broken is TLS? Why care?
2 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks How broken is TLS? Why care?
3 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
4 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
5 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
6 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
7 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
8 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
9 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
10 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
11 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
12 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
13 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
14 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
15 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
16 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
17 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
18 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
19 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
20 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
21 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
22 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
23 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
24 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
25 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks CA issues DNSSEC/DANE HTTP Public Key Pinning (HPKP) Certificate Transparency Free certificates
26 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Cipher suites Public key algorithms Key exchange Symmetric cryptography
27 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Cipher suites Public key algorithms Key exchange Symmetric cryptography
28 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Cipher suites Public key algorithms Key exchange Symmetric cryptography
29 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Cipher suites Public key algorithms Key exchange Symmetric cryptography
30 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Cipher suites Public key algorithms Key exchange Symmetric cryptography
31 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Cipher suites Public key algorithms Key exchange Symmetric cryptography
32 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Cipher suites Public key algorithms Key exchange Symmetric cryptography
33 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Cipher suites Public key algorithms Key exchange Symmetric cryptography
34 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks POODLE BERserk Others Other browsers Implementations
35 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks POODLE BERserk Others Other browsers Implementations
36 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks POODLE BERserk Others Other browsers Implementations
37 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks POODLE BERserk Others Other browsers Implementations
38 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks POODLE BERserk Others Other browsers Implementations
39 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks POODLE BERserk Others Other browsers Implementations
40 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks POODLE BERserk Others Other browsers Implementations
41 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks POODLE BERserk Others Other browsers Implementations
42 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks HTTPS by default Counterarguments HTTP Strict Transport Security (HSTS)
43 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks HTTPS by default Counterarguments HTTP Strict Transport Security (HSTS)
44 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks HTTPS by default Counterarguments HTTP Strict Transport Security (HSTS)
45 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks HTTPS by default Counterarguments HTTP Strict Transport Security (HSTS)
46 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks HTTPS by default Counterarguments HTTP Strict Transport Security (HSTS)
47 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks HTTPS by default Counterarguments HTTP Strict Transport Security (HSTS)
48 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks HTTPS by default Counterarguments HTTP Strict Transport Security (HSTS)
49 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks TLS 1.3 Quantum computers
50 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks TLS 1.3 Quantum computers
51 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Use HTTPS
52 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Use HTTPS
53 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Use HTTPS
54 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Use HTTPS
55 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Use HTTPS
56 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Use HTTPS
57 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Use HTTPS
58 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Use HTTPS
59 / 60
Introduction Certificate Authorities Algorithms Attacks HTTPS by default Future Final remarks Use HTTPS
60 / 60