BEAST
lorecryptographysecurity
A 2011 attack decrypting TLS 1.0 traffic by exploiting predictable CBC initialization vectors.
Browser Exploit Against SSL/TLS chained a chosen-plaintext trick with CBC's predictable IVs to recover secrets like cookies. It pushed the industry toward TLS 1.1+ and AEAD ciphers, and is why RC4 was briefly favored before its own weaknesses surfaced.
Also known as: BEAST, Browser Exploit Against SSL/TLS, CVE-2011-3389
Sources
- Browser Exploit Against SSL/TLS (2011)