6 ms·
One interesting thing about this is how it can lead to timing attacks which leak information about your keystrokes. There's a great paper [1] which gives some
by msmith 13y ago
One interesting thing about this is how it can lead to timing attacks which leak information about your keystrokes. There's a great paper [1] which gives some examples. One more reason to use pubkey authentication for SSH.
[1] http://users.ece.cmu.edu/~dawnsong/papers/ssh-timing.pdf http://users.ece.cmu.edu/~dawnsong/papers/ssh-timing.pdf
- M4v3R 13y agoThanks for this link, that was very educating! I had no idea that you could do stuff like this.
- betterunix 13y agoI believe that passwords are not transmitted like this in SSHv2 because of that very attack (not to say there are not overwhelmingly good reasons to use public key authentication anyway).
- theg5prank 13y agoThey can still get you if you invoke SSH on the remote, as the password is sent to the remote machine one character at a time, then forwarded on to your ultimate destination all at once.
- betterunix 13y agoGood point, though I imagine that this issue could be fixed in SSH as long as the password is not being echoed (which it should not be).
- msmith 13y agoIronically, I think it's actually slightly easier for an eavesdropper to detect that your keystrokes are part of a password if the password is not being echoed. They could potentially use this information to know the length of a password, which would make brute-forcing easier. A very hypothetical attack, but fun to think about! Less effective than a $5 wrench, no doubt.
- ddunkin 13y agoThat is what public key/agent forwarding is for. This will explain it better than I ever could: http://www.unixwiz.net/techtips/ssh-agent-forwarding.html http://www.unixwiz.net/techtips/ssh-agent-forwarding.html