YoVDO

Content-Type - multipart/oracle - Tapping into Format Oracles in Email End-to-End Encryption

Offered By: USENIX via YouTube

Tags

USENIX Security Courses Cybersecurity Courses Side Channel Attacks Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore a 14-minute conference talk from USENIX Security '23 that delves into format oracle attacks in email end-to-end encryption (E2EE). Learn how researchers surveyed potential remote methods for attackers to discover decryption states in email E2EE, analyzing the interaction between MIME and IMAP protocols. Discover side-channels emerging from network patterns that leak decryption status in Mail User Agents (MUAs). Understand the specific MIME trees that produce decryption-dependent network patterns when opened in email clients. Examine the survey results of 19 OpenPGP- and S/MIME-enabled email clients and four cryptographic libraries, revealing a side-channel vulnerability in one client. Discuss the practical challenges of exploitation in other clients due to missing feature support and implementation quirks. Consider the conflict between usability and security created by these unintended defenses. Gain insights into proposed countermeasures for MUA developers and standards to prevent exploitation in email E2EE systems.

Syllabus

USENIX Security '23 - Content-Type: multipart/oracle - Tapping into Format Oracles in Email...


Taught by

USENIX

Related Courses

Computer Security
Stanford University via Coursera
Cryptography II
Stanford University via Coursera
Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Building an Information Risk Management Toolkit
University of Washington via Coursera
Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network