Limitless HTTP in an HTTPS World: Inferring the Semantics of the HTTPS Protocol without Decryption presented at CODASPY2019 2019

by Scott Dunlop, David Mcgrew, Blake Anderson, Andrew Chi,

Scott Dunlop: Mr. Dunlop is a Senior Security Consultant at IOActive, experienced in application assessment and consultation. At IOActive he performs penetration testing, identifies system vulnerabilities, and designs custom security solutions for clients in software development, telecommunications, financial services, and professional services. Previous public works include MOSREF, a secure remote execution framework for penetration testers, and Wasp Lisp, a compact, portable Lisp implementation with strong concurrency features.