charonn0,
@charonn0@startrek.website avatar

Even the researcher who reported this doesn’t go as far as this headline.

“I am an admin, should I drop everything and fix this?”

Probably not.

The attack requires an active Man-in-the-Middle attacker that can intercept and modify the connection’s traffic at the TCP/IP layer. Additionally, we require the negotiation of either ChaCha20-Poly1305, or any CBC cipher in combination with Encrypt-then-MAC as the connection’s encryption mode.

[…]

“So how practical is the attack?”

The Terrapin attack requires an active Man-in-the-Middle attacker, that means some way for an attacker to intercept and modify the data sent from the client or server to the remote peer. This is difficult on the Internet, but can be a plausible attacker model on the local network.

terrapin-attack.com

  • All
  • Subscribed
  • Moderated
  • Favorites
  • linux@lemmy.ml
  • localhost
  • All magazines
  • 200 @ entry_comment_voters
    HTTP status 200 OK
    Route name entry_comment_voters
    Has session yes
    Stateless Check no
    Time 974 ms
    Total time 974 ms
    Initialization time 198 ms
    Memory 14.0 MiB
    Peak memory usage 14.0 MiB
    PHP memory limit 128 MiB
    Logger 87
    Errors 0
    Warnings 0
    Deprecations 87
    Cache 27 in 200.34 ms
    Cache Calls 27
    Total time 200.34 ms
    Cache hits 32 / 39 (82.05%)
    Cache writes 2
    2
    Default locale en
    Missing messages 2
    Fallback messages 0
    Defined messages 118
    Security n/a
    Authenticated No
    Firewall name main
    Twig 431 ms
    Render Time 431 ms
    Template Calls 65
    Block Calls 16
    Macro Calls 6
    41 in 297 ms
    settings_row_switch 15
    user_settings_row_switch 4
    date 3
    user_inline 2
    settings_row_enum 2
    entry_comment 1
    date_edited 1
    user_avatar 1
    vote 1
    boost 1
    user_actions 1
    magazine_box 1
    magazine_sub 1
    related_magazines 1
    active_users 1
    related_categories 1
    related_posts 1
    related_entries 1
    support_us_block 1
    featured_magazines 1
    11 in 88.91 ms
    Database Queries 11
    Different statements 10
    Query time 88.91 ms
    Invalid entities 0
    Cache hits 24
    Cache misses 2
    Cache puts 2
    6.4.0
    Profiler token 5033c2
    Environment dev
    Debug enabled
    PHP version 8.2.26   View phpinfo()
    PHP Extensions Xdebug ✗ APCu ✓ OPcache ✓
    PHP SAPI apache2handler