IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

RE: AEAD in ssh



On Wed, 24 Feb 2016, Peter Gutmann wrote:

> They actually leak nothing, in that encrypting the length provides no
> security benefit at all. See for example "Peek-a-Book, I Still See
> You: Why Efficient Traffic Analysis Countermeasures Fail" by Dyer,
> Coult, Ristenpart and Shrimpton. Their analysis, of TLS traffic with
> unencrypted lengths, completely ignores TLS' plaintext length fields
> because they're irrelevant.

Peek-a-Boo makes clear that encrypted lengths aren't *sufficient*, but
I don't think it's so clear that they aren't necessary or useful.

-d



Home | Main Index | Thread Index | Old Index