RE: AEAD in ssh

Peter Gutmann <[email protected]>
Newsgroups gmane.ietf.secsh
Message-ID <9A043F3CF02CD34C8E74AC1594475C73F4BE1D90@uxcn10-5.UoA.auckland.ac.nz>
denis bider <[email protected]> writes:

>I have recently implemented AES-GCM, and I find the choice of unencrypted
>length fields dubious. It negates any means of obfuscating the lengths of some
>packets using SSH_MSG_IGNORE.
>
>The alternative - to encrypt packet lengths using a parallel construction -
>seems much preferable.

See "Peek-a-Book, I Still See You: Why Efficient Traffic Analysis
Countermeasures Fail" by Dyer, Coult, Ristenpart and Shrimpton.  The
conclusion from the research: It's completely pointless, none of their attacks
even bother looking at the length field, so encrypting it is entirely
irrelevant.

Or, more importantly, it offers negative utility in that it makes processing
much harder and has led to exploitable vulnerabilities in the past.

Peter.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.