Ronald Petrlic, Klaus Manny: Wie sicher ist der Zugriff auf Websites im Internet? In: Datenschutz und Datensicherheit – DuD. Band41, Nr.2, 3. Februar 2017, ISSN1614-0702, S.88–92, doi:10.1007/s11623-017-0734-y.
Serge Vaudenay: Security Flaws Induced by CBC Padding Applications to SSL, IPSEC, WTLS… In: Advances in Cryptology – EUROCRYPT 2002 (= Lecture Notes in Computer Science). Band2332. Springer, Berlin / Heidelberg 2002, S.535–545, doi:10.1145/586110.586125 (iacr.org [PDF]).
Nadhem J. AlFardan, Kenneth G. Paterson: Lucky Thirteen: Breaking the TLS and DTLS Record Protocols. In: IEEE Symposium on Security and Privacy. IEEE, 2013, S.526–540, doi:10.1109/SP.2013.42 (ieee-security.org [PDF]).
Gregory V. Bard: The Vulnerability of SSL to Chosen Plaintext Attack. In: Cryptology ePrint Archive. 2004, doi:10.1145/586110.586125 (iacr.org [PDF]).
Benjamin Beurdouche, Karthikeyan Bhargavan, Antoine Delignat-Lavaud, Cédric Fournet, Markulf Kohlweiss, Alfredo Pironti, Pierre-Yves Strub, Jean Karim Zinzindohoue: A Messy State of the Union: Taming the Composite State Machines of TLS. In: IEEE Symposium on Security and Privacy. IEEE, 2015, S.535–552, doi:10.1109/SP.2015.39 (research.microsoft.com [PDF]).
David Adrian, Karthikeyan Bhargavan, Zakir Durumeric, Pierrick Gaudry, Matthew Green, J. Alex Halderman, Nadia Heninger, Drew Springall, Emmanuel Thomé, Luke Valenta, Benjamin VanderSloot, Eric Wustrow, Santiago Zanella-Béguelin, Paul Zimmermann: Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security. ACM, New York 2015, S.5–17, doi:10.1145/2810103.2813707 (weakdh.org [PDF]).
Serge Vaudenay: Security Flaws Induced by CBC Padding Applications to SSL, IPSEC, WTLS… In: Advances in Cryptology – EUROCRYPT 2002 (= Lecture Notes in Computer Science). Band2332. Springer, Berlin / Heidelberg 2002, S.535–545, doi:10.1145/586110.586125 (iacr.org [PDF]).
eprint.iacr.org
Gregory V. Bard: The Vulnerability of SSL to Chosen Plaintext Attack. In: Cryptology ePrint Archive. 2004, doi:10.1145/586110.586125 (iacr.org [PDF]).
ieee-security.org
Nadhem J. AlFardan, Kenneth G. Paterson: Lucky Thirteen: Breaking the TLS and DTLS Record Protocols. In: IEEE Symposium on Security and Privacy. IEEE, 2013, S.526–540, doi:10.1109/SP.2013.42 (ieee-security.org [PDF]).
ietf.org
datatracker.ietf.org
RFC: 8446 – The Transport Layer Security (TLS) Protocol Version 1.3. August 2018 (englisch).
RFC: 3546 – Transport Layer Security (TLS) Extensions. (englisch).
S. Turner, T. Polk: RFC: 6176 – Prohibiting Secure Sockets Layer (SSL) Version 2.0. März 2011 (englisch).
R. Barnes, M. Thomson, A. Pironti, A. Langley: RFC: 7568 – Deprecating Secure Sockets Layer Version 3.0. Juni 2015 (englisch).
K. Moriarty, S. Farrell: RFC: 8996 – Deprecating TLS 1.0 and TLS 1.1. März 2021 (englisch).
RFC: 2246 – The TLS Protocol Version 1.0. Januar 1999 (englisch).
RFC: 6101 – The Secure Sockets Layer (SSL) Protocol Version 3.0. August 2011 (englisch).
RFC: 2712 – Addition of Kerberos Cipher Suites to Transport Layer Security (TLS). (englisch).
RFC: 2817 – Upgrading to TLS Within HTTP/1.1. (englisch).
Benjamin Beurdouche, Karthikeyan Bhargavan, Antoine Delignat-Lavaud, Cédric Fournet, Markulf Kohlweiss, Alfredo Pironti, Pierre-Yves Strub, Jean Karim Zinzindohoue: A Messy State of the Union: Taming the Composite State Machines of TLS. In: IEEE Symposium on Security and Privacy. IEEE, 2015, S.535–552, doi:10.1109/SP.2015.39 (research.microsoft.com [PDF]).
mitls.org
Benjamin Beurdouche, Karthikeyan Bhargavan, Antoine Delignat-Lavaud, Cédric Fournet, Markulf Kohlweiss, Alfredo Pironti, Pierre-Yves Strub, Jean Karim Zinzindohoue: A messy state of the union: Taming the Composite State Machines of TLS. (PDF) 2015, abgerufen am 11. Januar 2016 (Präsentationsfolien).
David Adrian, Karthikeyan Bhargavan, Zakir Durumeric, Pierrick Gaudry, Matthew Green, J. Alex Halderman, Nadia Heninger, Drew Springall, Emmanuel Thomé, Luke Valenta, Benjamin VanderSloot, Eric Wustrow, Santiago Zanella-Béguelin, Paul Zimmermann: Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security. ACM, New York 2015, S.5–17, doi:10.1145/2810103.2813707 (weakdh.org [PDF]).
Ronald Petrlic, Klaus Manny: Wie sicher ist der Zugriff auf Websites im Internet? In: Datenschutz und Datensicherheit – DuD. Band41, Nr.2, 3. Februar 2017, ISSN1614-0702, S.88–92, doi:10.1007/s11623-017-0734-y.