Completed
Conclusions
Class Central Classrooms beta
YouTube videos curated by Class Central.
Classroom Contents
Efail - Breaking S-MIME and OpenPGP Email Encryption Using Exfiltration Channels
Automatically move to the next video in the Classroom when playback concludes
- 1 Intro
- 2 History of secure email
- 3 Two competing standards
- 4 Motivation for using end-to-end encryption
- 5 Both standards use old crypto
- 6 Old crypto has no negative impact
- 7 Backchannel techniques
- 8 Evaluation of backchannels in email clients
- 9 Attacker model
- 10 Hybrid encryption
- 11 Hybrid malleability of CBC/CFG
- 12 Malleability of CBC/CFB
- 13 Overview
- 14 Practical Attack against S/MIME
- 15 OpenPGP - Integrity Protection
- 16 RFC4880 on Modification Detection Codes
- 17 OpenPGP - Compression (DEFLATE)
- 18 Impact on the standards
- 19 Direct exfiltration - Demo Time
- 20 Conclusions
- 21 Black Hat sound bytes