Interesting -- looks as though the speculation as to the nature of CRIME was pretty much dead-on. Took years for anyone to realize that compression introduced a vulnerability into HTTPS, but as soon as everyone knew that there was something there, the nature of the attack was immediately guessed.
(Although I'd be much more worried if the community had discovered a different vulnerability!)
Comments
Interesting -- looks as though the speculation as to the nature of CRIME was pretty much dead-on. Took years for anyone to realize that compression introduced a vulnerability into HTTPS, but as soon as everyone knew that there was something there, the nature of the attack was immediately guessed.
(Although I'd be much more worried if the community had discovered a different vulnerability!)
People have been thinking about this sort of attack since at least 2002 http://www.iacr.org/cryptodb/data/paper.php?pubkey=3091