IETF-SSH archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
"arcfour-fixes" draft
As [SSH-TRANS] mentions, its definition of the "arcfour" algorithm suffers
from weak keys. I've written a specification for a variant of the
algorithm that prevents this by just discarding the beginning of the
Arcfour keystream. I've posted it as <http://www.ietf.org/
internet-drafts/draft-harris-ssh-arcfour-fixes-00.txt>, and invite the WG
to comment on it. I think this is at least as important as newmodes, but
I appreciate that it may be rather too late to get it turned into a WG
draft.
Incidentally, having read more of Fluhrer and McGrew's paper, I think my
recommendation in the Security Considerations section to rekey every 1G of
data is useless and I intend to remove it in the next revision. I'll try
to work out some text that describes the real impact of their
discriminator to replace it.
--
Ben Harris
Home |
Main Index |
Thread Index |
Old Index