SLOTH

lore

cryptography

A 2016 set of attacks abusing obsolete hashes like MD5 in TLS negotiation.

Security Losses from Obsolete and Truncated Transcript Hashes showed that allowing weak hashes such as MD5 in TLS signatures enabled transcript-collision and downgrade attacks. It pushed removal of MD5-based signatures from TLS.

Also known as: SLOTH, Security Losses from Obsolete and Truncated Transcript Hashes

Sources

  • SLOTH attack (2016)

All glossary entries