3 ms·
Datagrams are encrypted and authenticated using AES-128 in OCB mode. I'm curious to know more details. Does it leverage existing SSH auth infrastructure (i
by redbad 15y ago
Datagrams are encrypted and authenticated using
AES-128 in OCB mode.
I'm curious to know more details. Does it leverage existing SSH auth infrastructure (ie. keys) for that, somehow?
- keithwinstein 15y agoNot exactly, no -- it's a new roaming secure datagram protocol. It uses SSH for the initial key _exchange_: if you run "mosh-server" by itself, you'll see it spit out a random 128-bit session key that protects the mosh session.
- marshray 15y agoIs the protocol documented? I've looked at DTLS and I'm wondering how you prevent replay attacks and such.
- keithwinstein 15y agoIt is documented in the research paper linked from the site, yeah. The big contribution with this protocol is that every authenticated datagram represents an idempotent operation on the recipient, so we don't have to worry about replay attacks as such.
- marshray 14y agoI'm not sure how a terminal session can use only idempotent operations, but it sounds cool. I'll have to read the paper!