A Solution to Compression Oracles on the Web
This is a guest post by Blake Loring, a PhD student at Royal Holloway, University of London. Blake worked at Cloudflare as an intern in the summer of 2017.
Compression is often considered an essential tool when reducing the bandwidth usage of internet services. The impact that the use of such compression schemes can have on security, however, has often been overlooked. The recently detailed CRIME, BREACH, TIME and HEIST attacks on TLS have shown that if an attacker can make requests on behalf of a user then secret information can be extracted from encrypted messages using only the length of the response. Deciding whether an element of a web-page should be secret often depends on the content of the page, however there are some common elements of web-pages which should always remain secret such as Cross-Site Request Forgery (CSRF) tokens. Such tokens are used to ensure that malicious webpages cannot forge requests from a user by enforcing that any request must contain a secret token included in a previous response.
I worked at Cloudflare last summer to investigate possible solutions to this problem. The result is a project called cf-nocompress. The Continue reading

Bare metal switch revenue was up 60 percent year-over-year in the fourth quarter of 2017. And it’s projected to reach $3.6 billion in 2022, with cloud deployments as the primary driver.
Step up or get out of the way, say the operator board members of ONF, including AT&T, China Unicom, Comcast, Google, Deutsche Telekom, NTT Group, Telefonica, and Turk Telekom.

Looking into the world of manufacturing and how its modernizing can help to understand the intricacies of intent-based approaches and how they can be applied to storage.