Re: Binary packet protocol rethink
[email protected] (Niels Möller)
| Newsgroups | gmane.ietf.secsh |
|---|---|
| Message-ID | <[email protected]> |
Peter Gutmann <[email protected]> writes: > You get traffic analysis resistance by, for example, breaking data into > fixed-length packets, using cover traffic, and messing with packet > timings, not by encrypting TLS headers. One can do all of these with the current ssh wire protocol. It's even straight-forward to do. But if we switch to clear text lengths (with no other, deeper, changes to the protocol), it gets a lot more difficult. So encrypted packet lengths aren't a solution, but they're a *prerequisite* for the more serious counter measures. Regards, /Niels -- Niels Möller. PGP-encrypted email is preferred. Keyid C0B98E26. Internet email is subject to wholesale government surveillance.