BEAST

lore

cryptographysecurity

A 2011 attack decrypting TLS 1.0 traffic by exploiting predictable CBC initialization vectors.

Browser Exploit Against SSL/TLS chained a chosen-plaintext trick with CBC's predictable IVs to recover secrets like cookies. It pushed the industry toward TLS 1.1+ and AEAD ciphers, and is why RC4 was briefly favored before its own weaknesses surfaced.

Also known as: BEAST, Browser Exploit Against SSL/TLS, CVE-2011-3389

Sources

  • Browser Exploit Against SSL/TLS (2011)

All glossary entries