Re: Terrapin
Peter Gutmann <[email protected]> Sat, 30 Dec 2023 07:05:14 +0000
| Newsgroups | gmane.ietf.secsh |
|---|---|
| Message-ID | <SY4PR01MB62519A632EDA2D4A25FACDD4EE9CA@SY4PR01MB6251.ausprd01.prod.outlook.com> |
Mouse <[email protected]> writes:=0A=0A>I've mentioned my own unde= rstanding of the reason on-list recently; search=0A>for "SandP" in your bac= k mail, or the archives if need be. (Most briefly, my=0A>understanding is t= hat it's to defeat an attack, but in my opinion there are=0A>better defense= s.)=0A=0AI saw that, but the link posted is 404 (or at least "MySQL error")= , I assume=0Ait's the Paterson et al paper from 2009? I can see that, due = the use of AES-=0ACTR in GCM, an attacker can make you see anything they wa= nt in the decrypted=0Apacket rather than the CBC alternative where they jus= t have to hope for the=0Abest (with low probability), but if you've already= closed that hole, or never=0Ahad it in the first place, I can't see what d= ifference it'd make. From the=0Acode changes I had to make I'd say all the= special-snowflake code added to=0Asupport EtM-OpenSSH is probably a much b= igger issue in terms of attack=0Asurface.=0A=0APeter.