3 ms·
Good old RSA once again proves it can be trusted, whereas these newer crypto systems made in the last decade disappoint over and over again. Yet people keep usi
by forward1 3y ago
Good old RSA once again proves it can be trusted, whereas these newer crypto systems made in the last decade disappoint over and over again. Yet people keep using them because they're told they are fashionable, without really knowing the full implications.
- TontonNestor 3y agoAs far as I can tell, this has nothing to do with the public key cryptography used in the protocol.
- manchmalscott 3y agoFrom the original paper: > ChaCha20-Poly1305 [30] directly uses the sequence number in its key derivation, which makes it vulnerable to our prefix truncation attack... > Note that the fault is not with ChaCha20-Poly1305 as an AEAD encryption scheme, but with its integration into the SSH secure channel construction. See here: https://terrapin-attack.com/TerrapinAttack.pdf https://terrapin-attack.com/TerrapinAttack.pdf