RE: AEAD in ssh

Peter Gutmann <[email protected]>
Newsgroups gmane.ietf.secsh
Message-ID <9A043F3CF02CD34C8E74AC1594475C73F4BFF50B@uxcn10-5.UoA.auckland.ac.nz>
Niels Möller <[email protected]> writes:

>My understanding is that cleartext length fields are believed to be secure,
>in that the only thing leaked are message boundaries.

They actually leak nothing, in that encrypting the length provides no security
benefit at all.  See for example "Peek-a-Book, I Still See You: Why Efficient
Traffic Analysis Countermeasures Fail" by Dyer, Coult, Ristenpart and
Shrimpton. Their analysis, of TLS traffic with unencrypted lengths, completely
ignores TLS' plaintext length fields because they're irrelevant.

The encryption-of-lengths debate is a classic example of the assume-a-can-
opener problem:

  A physicist, a chemist, and an economist were stranded on a desert island
  with no implements and a can of food. The physicist and the chemist each
  devised an ingenious mechanism for getting the can open; the economist
  merely said, "Assume we have a can opener".

Instead of debating endlessly over the most efficient way to apply the assumed
can opener (encryption of lengths), we need to look at whether it serves any
purpose (as Dyer at el point out, it doesn't), and if it does serve a purpose,
whether it's worth the tradeoffs involved in implementing it (for which see
the previous point).

Peter.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.