Wow. I've seen many compress-then-encrypt backup schemes, which I always thought is vulnerable to CRIME but should be hard to exploit due to a stupid assumption that it should be hard to force the target to perform repeated backups.
This tweet is unavailable

Jan 9, 2023 · 5:57 PM UTC

1
9
1
36
Replying to @XorNinja
fun but if attackers can do that then they can retrieve the keys in many different ways, right?
1
1