Common TLS Attacks
Downgrade and stripping.
TLS Is a Target
Because TLS protects so much traffic, attackers constantly look for weaknesses.
Most attacks try to downgrade security, strip encryption, or exploit old protocol flaws.
Downgrade Attacks
In a downgrade attack, an attacker interferes with the handshake to force both sides onto an older, weaker protocol or cipher.
The POODLE attack abused a forced downgrade to SSL 3.0.
All lessons in this course
- The TLS Handshake
- Cipher Suites
- Certificate Validation
- Common TLS Attacks