Re: Curve25519/448 key agreement for SSH
Simon Josefsson <[email protected]>
| Newsgroups | gmane.ietf.secsh |
|---|---|
| Message-ID | <[email protected]> |
denis bider <[email protected]> writes: > Simon - > > >> A simple approach would be to say that if the MSB is 1, >> prepend a zero byte. However, the length difference >> would leak that information. > > The length difference might not be much of a problem, since K is never sent. It shouldn't be difficult to fingerprint (statistically, over many connections) if a remote application performs a hash on X bytes or X+1 bytes. Knowing which leaks the MSB of the derived secret. I'm inclined to add a security consideration describing this, and allow for the potential of a nice conference paper describing how to exploit this observation. At this point, to fix this (as Damien described) appear less appealing. /Simon
signature.asc
(application/pgp-signature, 472 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQEcBAEBCAAGBQJWRFLPAAoJEIYLf7sy+BGdjkkH+wW+ERcS4dUeeYfA1S3ye7vX 5yummOD+pQRrbKjqyU02KEq2qzX7vwEXX1zFXS8ltXNMNCam/pu29DK30fnDDKyz x0VgVvtVIc9mfgKIJeXGROKCBZjKB92+ayMEixtCqOVjgAKP4nIM7sEkQQxbf5p9 nFYOFiOB4CTbiUAJRePPU9xHpJWPzHOGx4Ko2LVj07xkp5gR08MZ7teYNn2aTk2G MaklvFRxYfWFJ8GK/p8PNU5sgh3++7bXJ36nB2gArK6UNTACO0nUwEkm+4AoUGIG 1b/U5EgQ+bfZ8ghHHFaoH8X2KYraEXA02Ns0l/h+ap4wdxPe9rmLG34vkABpGpg= =dD0v -----END PGP SIGNATURE-----