Re: Albrecht/Paterson/Watson's attack

Peter Gutmann <[email protected]>
Newsgroups gmane.ietf.secsh
Message-ID <[email protected]>
Niels Möller <[email protected]> writes:

>I think that would be good.

+1 (conflict-of-interest disclaimer: I'm the author of the TLS EtM draft). 

One thing that SSH would then need to do is to stop encrypting the header
(that is, the length information) so you can run the MAC over the packet
without having to pick apart bits of it via decryption first, which is what
helps the Paterson et al attack work.  The TLS draft explicitly tells
implementers to read the length, read that many bytes from the network, run
the MAC, and discard the packet immediately if the MAC fails to verify.  If
you still need to run crypto ops before you can verify the MAC you're not
actually doing EtM, or at least not getting the security benefits that it
provides.

Peter.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.