Quantcast
Channel: Bountied questions - Information Security Stack Exchange
Viewing all articles
Browse latest Browse all 154

Triple handshake attack - what are the implications of not supporting RFC 7627: "Session Hash and Extended Master Secret Extension"?

$
0
0

The referenced RFC details a mitigation to what appears to be the ability to compromise a TLS connection through an attack known as the 'triple handshake attack'.

How serious is this vulnerability? How could this vulnerability be exploited and what would the impact be?

The related RFC for this can be found here: https://tools.ietf.org/html/rfc7627


Viewing all articles
Browse latest Browse all 154

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>