11 ms·
This looks very useful, but I'm concerned about its security since anything entered on keyboard will be sent over Ethernet in cleartext. I think even if you en
by kramerger 3y ago
This looks very useful, but I'm concerned about its security since anything entered on keyboard will be sent over Ethernet in cleartext.
I think even if you encrypted the UDP packets you may still be vulnerable to timing side channel attacks:
https://www.usenix.org/conference/10th-usenix-security-symposium/timing-analysis-keystrokes-and-timing-attacks-ssh https://www.usenix.org/conference/10th-usenix-security-sympo...
- out-of-ideas 3y agowhile i do agree it should not be plaintext, i would likely still use this on my home network where i trust the devices on my network; though if for some reason i did not trust the devices on there, i would use wireguard between two systems as an added layer
- feschber 3y agoYes, absolutely. I have not gotten round to implementing that but its on the roadmap. The plan is to use https://crates.io/crates/webrtc-dtls https://crates.io/crates/webrtc-dtls. I dont think timing sidechannel attacks are a huge concern and they could be somewhat mitigated through phantom events.