On 9/10/2008 at 2:58 PM Kevin Neff wrote:
|Hi,
|
|Some secure protocols like SSH send encrypted keystrokes
|as they're typed. By doing timing analysis you can figure
|out which keys the user probably typed (keys that are
|physically close together on a keyboard can be typed
|faster). A careful analysis can reveal the length of
|passwords and probably some of password itself.
=============>> (keys that are physically close together on a keyboard
I do not agree with that statement. Using two fingers I can hit the "A" and
"L" keys nearly simultaneously (probably could even hit them simultaneously if
I tried enough).
The statement seems to rely upon the typist being a one-finger typer.
| Tarkan Erimer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Ingo Molnar | Re: [RFT] x86 acpi: normalize segment descriptor register on resume |
| Andrew Morton | -mm merge plans for 2.6.23 |
| Greg Kroah-Hartman | [PATCH 004/196] Chinese: add translation of SubmittingPatches |
git: | |
| Gerrit Renker | [PATCH 15/37] dccp: Set per-connection CCIDs via socket options |
| David Miller | Re: [GIT]: Networking |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Ingo Molnar | [bug] stuck localhost TCP connections, v2.6.26-rc3+ |
