"The illusion of challenge-response authentication"

Haya Shulmann · 2014

Most Internet services and systems still rely on challenge-response defences for their security against attacks by off-path adversaries. We present techniques allowing to subvert standard and widely supported defences, and show how to facilitate them for DNS cache poisoning attacks. We propose short term countermeasures, preventing our attacks, however, we argue that in the long term, cryptographic defences should be deployed, providing security even against stronger man-in-the-middle adversaries.

Read the paper · More papers on PaperTik