On Monday, November 20, 2006 02:58:18 PM +0000 Simon Tatham <anakin%pobox.com@localhost> wrote:
As far as I can see, the only _safe_ way for a client to implement this compression method as currently specified is to note it being offered in the initial kex, but not to accept that offer, and then to initiate a rekey after authentication in which we enable it.
... at which point, compression would start after SSH_MSG_NEWKEYS :-)