CAT -- TLS |
TLS. , RSA (Padding Oracle attack), (Daniel Bleichenbacher) .
CAT Padding Oracle ( ), , TLS. , ( ).
, (, Gmail) . , , , . FLUSH+RELOAD( , ), Browser Exploit Against SSL/TLS (BEAST) TLS (OpenSSL, Amazon s2n, MbedTLS, Apple CoreTLS, Mozilla NSS, WolfSSL, GnuTLS). BearSSL BoringSSL . CVE-2018-12404, CVE-2018-19608, CVE-2018-16868, CVE-2018-16869 CVE-2018-16870.
http://feedproxy.google.com/~r/org/LOR/~3/YQvrIuDp8lY/14649178