-
Notifications
You must be signed in to change notification settings - Fork 33
Open
Description
I was reading Secure Secure Shell, and found this near the end:
After some debate and going back and forth between including GCM or not, it’s now back again. The reason for dropping it was that SSH doesn’t encrypt packet sizes when using GCM. The reason for bringing it back is that SSH does the same with any EtM algorithms. There is no way around this unless you can live with chacha20-poly1305 only. Also, the leaked documents don’t sound like they can figure out the lengths or confirm presence of some things, more like straight up “send it to us and we’ll decrypt it for you”. Wrapping SSH in a Tor hidden service will take care of any traffic analysis concerns.
Well, chacha20-poly1305 has been proven hackable, it seems?
Metadata
Metadata
Assignees
Labels
No labels