Re: Patching a SSH 'Weakness'

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Paul de Weerd
Date: Thursday, September 11, 2008 - 1:49 am

On Thu, Sep 11, 2008 at 10:06:27AM +0900, Hari wrote:
| On Thu, Sep 11, 2008 at 4:58 AM, Kevin Neff <kevin.l.neff@gmail.com> wrote:
| > Hi,
| >
| > Some secure protocols like SSH send encrypted keystrokes
| > as they're typed.  By doing timing analysis you can figure
| > out which keys the user probably typed (keys that are
| > physically close together on a keyboard can be typed
| > faster).  A careful analysis can reveal the length of
| > passwords and probably some of password itself.
| >
| > The paper:
| >
| >  http://portal.acm.org/citation.cfm?
| >  id=1267612.1267637&coll=Portal&dl=GUIDE&CFID=1943417&C
| >  FTOKEN=28290455
| 
| The paper itself is not accessible. Prima facie, this looked like a
| technology-in-search-of-a-problem kinda thing to me. For now, it
| sounds like bull.

Sure the paper is accessible. Just google for "Timing Analysis of
Keystrokes and Timing Attacks on SSH". First hit is the PDF of the
article which is well written and explains the problem in great
detail.

Cheers,

Paul 'WEiRD' de Weerd

-- 
+++++++++++>-]<.>++[<------------>-]<+.--------------.[-]
                 http://www.weirdnet.nl/
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Patching a SSH 'Weakness', Kevin Neff, (Wed Sep 10, 12:58 pm)
Re: Patching a SSH 'Weakness', Damien Miller, (Wed Sep 10, 5:59 pm)
Re: Patching a SSH 'Weakness', Hari, (Wed Sep 10, 6:06 pm)
Re: Patching a SSH 'Weakness', Marco Peereboom, (Wed Sep 10, 6:50 pm)
Re: Patching a SSH 'Weakness', Darrin Chandler, (Wed Sep 10, 7:21 pm)
Re: Patching a SSH 'Weakness', STeve Andre', (Wed Sep 10, 7:56 pm)
Re: Patching a SSH 'Weakness', Aaron Glenn, (Wed Sep 10, 9:40 pm)
Re: Patching a SSH 'Weakness', Johan Beisser, (Wed Sep 10, 10:35 pm)
Re: Patching a SSH 'Weakness', Damien Miller, (Wed Sep 10, 11:28 pm)
Re: Patching a SSH 'Weakness', Paul de Weerd, (Thu Sep 11, 1:49 am)
Re: Patching a SSH 'Weakness', STeve Andre', (Thu Sep 11, 5:50 am)
Re: Patching a SSH 'Weakness', Giancarlo Razzolini, (Thu Sep 11, 8:06 am)
Re: Patching a SSH 'Weakness', Mike M, (Fri Sep 12, 5:01 am)
Re: Patching a SSH 'Weakness', Kevin Neff, (Fri Sep 12, 7:02 am)
Re: Patching a SSH 'Weakness', johan beisser, (Fri Sep 12, 2:32 pm)