[Resource Topic] 2004/203: How to Cheat at Chess: A Security Analysis of the Internet Chess Club

Welcome to the resource topic for 2004/203

Title:
How to Cheat at Chess: A Security Analysis of the Internet Chess Club

Authors: John Black, Martin Cochran, Ryan Gardner

Abstract:

The Internet Chess Club (ICC) is a popular online chess server with more than 30,000 members worldwide including various celebrities and the best chess players in the world. Although the ICC website assures its users that the security protocol used between client and server provides sufficient security for sensitive information to be transmitted (such as credit card numbers), we show this is not true. In particular we show how a passive adversary can easily read all communications with a trivial amount of computation, and how an active adversary can gain virtually unlimited powers over an ICC user. We also show simple methods for defeating the timestamping mechanism used by ICC. For each problem we uncover, we suggest repairs. Most of these are practical and inexpensive.

ePrint: https://eprint.iacr.org/2004/203

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .