Hi, Some secure protocols like SSH send encrypted keystrokes as they're typed. By doing timing analysis you can figure out which keys the user probably typed (keys that are physically close together on a keyboard can be typed faster). A careful analysis can reveal the length of passwords and probably some of password itself. The paper: http://portal.acm.org/citation.cfm? id=1267612.1267637&coll=Portal&dl=GUIDE&CFID=1943417&C FTOKEN=28290455 I'm seriously considering implementing a fix for this weakness. Is there any interest in incorporating this sort of thing into openBSD? Cheers --Kevin
| Linus Torvalds | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Rafael J. Wysocki | [Bug #10391] 2.6.25-rc7/8: Another resume regression |
| Arjan van de Ven | [Patch v2] Make PCI extended config space (MMCONFIG) a driver opt-in |
| Jeremy Fitzhardinge | Re: [RFC] Heads up on sys_fallocate() |
git: | |
| Martin Langhoff | Re: pack operation is thrashing my server |
| Arjen Laarhoven | [PATCH 1/2] t/t4202-log.sh: Add testcases |
| Li Frank-B20596 | why not TortoiseGit |
| sean | Re: Implementing branch attributes in git config |
| Diana Eichert | bcw(4) is gone |
| Nick Guenther | Re: Real men don't attack straw men |
| Khalid Schofield | Port ZFS to OpenBSD |
| Christopher Intemann | OpenBSD on Sun Netra X1 |
| Gerrit Renker | [PATCH 15/37] dccp: Set per-connection CCIDs via socket options |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Mark Smith | Is it valid to add a macvlan virtual interface to a bridge? If so, there seems to ... |
| Joakim Tjernlund | raw PF_PACKET protocol selection |
