[Cryptography] Downgrade attack on www.bloombergquint.com

Henry Baker hbaker1 at pipeline.com
Tue Jan 22 17:03:13 EST 2019


This isn't exactly crypto -- just obfuscation.

Bloomberg Quint -- whatever that is -- wants you
to sign in to see their articles, and if you don't,
they *blur* the text so that you can't read it.

However, if you simply put the same URL into
the *Lynx* ascii browser, you can read the text
just fine.

BTW, this downgrade attack also seems to work on
many sites that want you to do something before
they let you see the rest of their articles.



More information about the cryptography mailing list