Re: Binary packet protocol rethink

[email protected] (Niels Möller)
Newsgroups gmane.ietf.secsh
Message-ID <[email protected]>
Peter Gutmann <[email protected]> writes:

>   You get traffic analysis resistance by, for example, breaking data into 
>   fixed-length packets, using cover traffic, and messing with packet 
>   timings, not by encrypting TLS headers.

One can do all of these with the current ssh wire protocol. It's even
straight-forward to do. But if we switch to clear text lengths (with no
other, deeper, changes to the protocol), it gets a lot more difficult.

So encrypted packet lengths aren't a solution, but they're a
*prerequisite* for the more serious counter measures.

Regards,
/Niels

-- 
Niels Möller. PGP-encrypted email is preferred. Keyid C0B98E26.
Internet email is subject to wholesale government surveillance.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.