Re: Curve25519/448 key agreement for SSH

Simon Josefsson <[email protected]>
Newsgroups gmane.ietf.secsh
Message-ID <[email protected]>
denis bider <[email protected]> writes:

> Simon -
>
>
>> A simple approach would be to say that if the MSB is 1,
>> prepend a zero byte.  However, the length difference
>> would leak that information.
>
> The length difference might not be much of a problem, since K is never sent.

It shouldn't be difficult to fingerprint (statistically, over many
connections) if a remote application performs a hash on X bytes or X+1
bytes.  Knowing which leaks the MSB of the derived secret.

I'm inclined to add a security consideration describing this, and allow
for the potential of a nice conference paper describing how to exploit
this observation.  At this point, to fix this (as Damien described)
appear less appealing.

/Simon
signature.asc (application/pgp-signature, 472 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEcBAEBCAAGBQJWRFLPAAoJEIYLf7sy+BGdjkkH+wW+ERcS4dUeeYfA1S3ye7vX
5yummOD+pQRrbKjqyU02KEq2qzX7vwEXX1zFXS8ltXNMNCam/pu29DK30fnDDKyz
x0VgVvtVIc9mfgKIJeXGROKCBZjKB92+ayMEixtCqOVjgAKP4nIM7sEkQQxbf5p9
nFYOFiOB4CTbiUAJRePPU9xHpJWPzHOGx4Ko2LVj07xkp5gR08MZ7teYNn2aTk2G
MaklvFRxYfWFJ8GK/p8PNU5sgh3++7bXJ36nB2gArK6UNTACO0nUwEkm+4AoUGIG
1b/U5EgQ+bfZ8ghHHFaoH8X2KYraEXA02Ns0l/h+ap4wdxPe9rmLG34vkABpGpg=
=dD0v
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.