BREACH: the two Greek hackers who broke Facebook and Gmail

Two φαίνεται να κατέπληξαν τους πάντες στο Black Hat Asia 2016. Ο Δημήτρης Καρακώστας και ο Διονύσης Ζήνδρος αναβάθμισαν την επίθεση BREACH (Browser Reconnaissance and Exfiltration via Adaptive Compression of Hypertext) για να διαπερνά τους πιο κοινούς αλγόριθμους of the web.karakostas zindros BREACH

The two PhD students who presented the BREACH attack were even released and a framework which will help hackers (with good intentions) and information to spy on Facebook and Gmail.

dimitris karakostas dionysis zindros
Dimitris Karakostas (left) with Dionysis Zedrod. Picture: Darren Pauli The Register.

In Black Hat Asia, the pair once again proved that the Internet can not be the term security even in the most popular online services, investing a lot of money and labor hours to protect themselves.

The new version of BREACH (Browser Reconnaissance and Exfiltration via Adaptive Compression of Hypertext) is even more powerful: hackers can target "noisy" end-points that do not use strong encryption algorithms, including AES 128 bit.

They say the new attack is also 500 times faster than the original attack.

The original BREACH attack was released to Black Hat at 2013 and was internationally recognized. The attack offended the common Deflate data compression algorithm used to save bandwidth on Internet communications.

Karakostas and Zedros (@dionyziz) from the National Technical University of Athens and the University of Athens described the them in the document Practical New Developments on BREACH (PDF).

On stage at Black Hat Asia, they demonstrated how the attack could be used to read them of the victim on Facebook but also Gmail emails using it "Rupture" framework, which they have developed and makes attack much simpler.

An attack, however, is not a toy and said it would take weeks to successfully break a target.

The "Rupture" framework is open source and is developed by Ph.D. students of the group.

Code

Whitepaper

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).