Security and Compression


Details
Agenda
-
Chapter Intro
-
Main presentation: Title: Security and Compression
Author: Lucas Driscoll https://github.com/Lukerd-29-00/
Abstract: This is a talk on the cybersecurity risks caused by using compression, especially in a web context. It goes over the basic mechanics of attacking a scheme where text is compressed and then encrypted, the attacks that have been discovered in practice, and mitigations against them.
This relates to attacks against TLS, such as Compression Ratio Info-leak Made Easy (CRIME) and BREACH (Browser Reconnaissance and Exfiltration via Adaptive Compression of Hypertext) .
- Web Academy hands-on labs - We continue our journey through the Web Academy at https://portswigger.net/web-security/
The meeting will be held in the library's computer lab to encourage people to get some hands-on web security testing experience.

Sponsors
Security and Compression