<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kryptering - Information och nyheter om krypto &#187; sidokanal</title>
	<atom:link href="http://kryptera.se/t/sidokanal/feed/" rel="self" type="application/rss+xml" />
	<link>http://kryptera.se</link>
	<description>Senaste nytt om kryptering och krypto</description>
	<lastBuildDate>Mon, 06 Sep 2010 19:52:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/>		<item>
		<title>Sidokanalsattacker mot HTTPS</title>
		<link>http://kryptera.se/sidokanalsattacker-mot-https/</link>
		<comments>http://kryptera.se/sidokanalsattacker-mot-https/#comments</comments>
		<pubDate>Sat, 27 Mar 2010 11:36:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Okategoriserade]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[sidokanal]]></category>
		<category><![CDATA[sidokanalsattacker]]></category>

		<guid isPermaLink="false">http://kryptera.se/?p=355</guid>
		<description><![CDATA[Om någon kan avlyssna din förbindelse och se hur stora paket som skickas samt om den som avlyssnar även kan besöka https-sidan så är det möjligt för den som avlyssnar att lista ut vilka sidor du besöker. Abstract. With software-as-a-service becoming mainstream, more and more applications are delivered to the client through the Web. Unlike [...]<p>F&ouml;lj oss p&aring; Twitter: <a href="http://twitter.com/kryptera">http://twitter.com/kryptera</a></p>
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://kryptera.se/sidokanalsattacker-mot-https/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' /></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fkryptera.se%2Fsidokanalsattacker-mot-https%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fkryptera.se%2Fsidokanalsattacker-mot-https%2F&amp;source=kryptera&amp;style=compact" height="61" width="50" /><br />
			</a>
		</div>
<p>Om någon kan avlyssna din förbindelse och se hur stora paket som skickas samt om den som avlyssnar även kan besöka https-sidan så är det möjligt för den som avlyssnar att lista ut vilka sidor du besöker.</p>
<blockquote><p><strong>Abstract.</strong> With software-as-a-service becoming mainstream, more  and more applications are delivered to the client through the Web.  Unlike a desktop application, a web application is split into  browser-side and server-side components. A subset of the application&#8217;s  internal information flows are inevitably exposed on the network. We  show that despite encryption, such a side-channel information leak is a  realistic and serious threat to user privacy. Specifically, we found  that surprisingly detailed sensitive information is being leaked out  from a number of high-profile, top-of-the-line web applications in  healthcare, taxation, investment and web search: an eavesdropper can  infer the illnesses/medications/surgeries of the user, her family income  and investment secrets, despite HTTPS protection; a stranger on the  street can glean enterprise employees&#8217; web search queries, despite  WPA/WPA2 Wi-Fi encryption. More importantly, the root causes of the  problem are some fundamental characteristics of web applications:  stateful communication, low entropy input for better interaction, and  significant traffic distinctions. As a result, the scope of the problem  seems industry-wide. We further present a concrete analysis to  demonstrate the challenges of mitigating such a threat, which points to  the necessity of a disciplined engineering practice for side-channel  mitigations in future web application developments.</p></blockquote>
<p>Dokumentet hittas här: <a href="http://www.informatics.indiana.edu/xw7/WebAppSideChannel-final.pdf">informatics.indiana.edu/xw7/WebAppSideChannel-final.pdf</a></p>
<p>Via <a href="http://www.schneier.com/blog/archives/2010/03/side-channel_at.html">Bruce Schnier</a>.</p>
<p>F&ouml;lj oss p&aring; Twitter: <a href="http://twitter.com/kryptera">http://twitter.com/kryptera</a></p>
]]></content:encoded>
			<wfw:commentRss>http://kryptera.se/sidokanalsattacker-mot-https/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Side channel (sidokanals) attacker</title>
		<link>http://kryptera.se/side-channel-sidokanals-attacker/</link>
		<comments>http://kryptera.se/side-channel-sidokanals-attacker/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 14:46:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Okategoriserade]]></category>
		<category><![CDATA[ieee]]></category>
		<category><![CDATA[side-channel]]></category>
		<category><![CDATA[sidokanal]]></category>

		<guid isPermaLink="false">http://kryptera.se/?p=325</guid>
		<description><![CDATA[Kryptografiska side channel attacker eller på svenska sidokanals-attacker beskrivs mycket bra i nedan dokument utgivet av IEEE. F&#246;lj oss p&#229; Twitter: http://twitter.com/kryptera<p>F&ouml;lj oss p&aring; Twitter: <a href="http://twitter.com/kryptera">http://twitter.com/kryptera</a></p>
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://kryptera.se/side-channel-sidokanals-attacker/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' /></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fkryptera.se%2Fside-channel-sidokanals-attacker%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fkryptera.se%2Fside-channel-sidokanals-attacker%2F&amp;source=kryptera&amp;style=compact" height="61" width="50" /><br />
			</a>
		</div>
<p>Kryptografiska <a href="/t/side-channel">side channel</a> attacker eller på svenska <a href="/t/sidokanal">sidokanals-attacker</a> beskrivs mycket bra i nedan dokument utgivet av IEEE.</p>
<p><object id="doc_372494331230252" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="500" height="500" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="name" value="doc_372494331230252" /><param name="align" value="middle" /><param name="quality" value="high" /><param name="play" value="true" /><param name="loop" value="true" /><param name="scale" value="showall" /><param name="wmode" value="opaque" /><param name="devicefont" value="false" /><param name="bgcolor" value="#ffffff" /><param name="menu" value="true" /><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="mode" value="list" /><param name="src" value="http://d1.scribdassets.com/ScribdViewer.swf?document_id=24633069&amp;access_key=key-jys8psbw51g1447a92v&amp;page=1&amp;version=1&amp;viewMode=list" /><param name="allowfullscreen" value="true" /><embed id="doc_372494331230252" type="application/x-shockwave-flash" width="500" height="500" src="http://d1.scribdassets.com/ScribdViewer.swf?document_id=24633069&amp;access_key=key-jys8psbw51g1447a92v&amp;page=1&amp;version=1&amp;viewMode=list" mode="list" allowscriptaccess="always" allowfullscreen="true" menu="true" bgcolor="#ffffff" devicefont="false" wmode="opaque" scale="showall" loop="true" play="true" quality="high" align="middle" name="doc_372494331230252"></embed></object></p>
<p>F&ouml;lj oss p&aring; Twitter: <a href="http://twitter.com/kryptera">http://twitter.com/kryptera</a></p>
]]></content:encoded>
			<wfw:commentRss>http://kryptera.se/side-channel-sidokanals-attacker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
