Logjam TLS attack
weakdh.org
Logjam TLS attack
1–10 of 103 posts
Re: Logjam TLS attack
#2Re: Logjam TLS attack
#3But, if you need to spend the time updating a server configuration, just switch to ECDHE instead.
Re: Logjam TLS attack
#4Also, scary that SSH appears to be partially affected(?)
Re: Logjam TLS attack
#5One small nit with the paper: it is claimed that there had been technical difficulties with the individual logarithm step of the NFS applied to discrete logarithms, making individual logs asymptotically as expensive as the precomputation. Commeine and Semaev [1] deserve the credit for breaking this barrier; Barbulescu did improve their L[1/3, 1.44] to L[1/3, 1.232] by using smarter early-abort strategies, but was not the first to come up with 'cheap' individual logs.
Re: Logjam TLS attack
#6Re: Logjam TLS attack
#7I'm using Version 42.0.2311.152 (64-bit) Chrome, so far it's still vulnerable to this. I believe it's the latest production version.
Re: Logjam TLS attack
#8I'm using Version 42.0.2311.152 (64-bit) Chrome, so far it's still vulnerable to this. I believe it's the latest production version.
I'm running Version 43.0.2357.65 (64-bit) Chrome, which is also vulnerable to this. I believe it's the latest production version.
Re: Logjam TLS attack
#9Use a proper ciphersuite and stop worrying about downgrade attacks. https://wiki.mozilla.org/Security/Server_Side_TLS