IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: draft-ietf-secsh-newmodes-01.txt: WG Last Call!




Of course, this doens't mean that it's harmless to reuse the sequence
number. Reusing the sequence number makes it possible for an attacker
to replay ssh packets (this is also documented in the BKN paper).

To me, replay attacks are a more compelling reason to avoid sequence
number reuse than the information leak, and I think the newmodes
document should mention this class of attacks.



Thank you for pointing this out. Yes, we seem to have failed to mention this in the current version of the Internet-Draft. We will fix this in the next version.

Yoshi




Home | Main Index | Thread Index | Old Index