4 ms·
Can't we do both? Like, the content of the UDP packet is the output of `date -uIs | gpg --sign`.
by heftig 6y ago
Can't we do both? Like, the content of the UDP packet is the output of `date -uIs | gpg --sign`.
- cheweh 6y agoFrom knockknock: > When you want to open a port from a client, you run 'knockknock', which sends a single SYN packet to the server. The packet's IP and TCP headers are encoded to represent an IND-CCA secure encrypted request to open a specified port from the source IP address. https://moxie.org/software/knockknock/ https://moxie.org/software/knockknock/
- cutemonster 6y agoThat page links to a http insecure download script, weird. (Not https, no signature) This link: wget http://www.thoughtcrime.org/software/knockknock/knockknock-0.6.tar.gz http://www.thoughtcrime.org/software/knockknock/knockknock-0...
- Forbo 6y agoYeah, the documentation is dated. Not only does it point to an old version, but it would probably be best to get it from the GitHub page he links to. Even then, there are more active forks, so they may be worth checking out to see which would be best to get on board with.
- cutemonster 6y agoThanks, seems this is the (also outdated) repo: https://github.com/moxie0/knockknock https://github.com/moxie0/knockknock Yes I suppose one of the forks is better nowadays
- steerablesafe 6y agoYou already do both when you are concealing an ssh server. The cryptography part is the responsibility of the ssh server. edit: That specific scheme looks naive and susceptible to replay attacks.
- moring 6y agoThe suggestion is nice though since an attacker would have to break both at once. If you conceal an SSH server, you'd first break the obscurity, then proceed with attacking the SSH server. The suggestion seems to be that you would have to break the cryptographic part to reveal the server (which is then supposedly secured by "normal" cryptographic means, such as a regular SSH server). That is, you are dealing with cryptography just to be sure the server exists at all.
- steerablesafe 6y agoI'm all for defense in depth but I don't see the point of a redundant cryptographic layer. It's not trivial that it doesn't broaden the attack surface instead of narrowing it. If the argument is that a steganographic layer that involves cryptography does a better job at concealing than a similar layer that doesn't I'm also not convinced. Cryptography helps against MITM scenarios, but at that point the existence of the service is already revealed.