3 ms·
> signed data include session id that is derived from result of first DH key exchange and thus unpredictable to either side of connection The unpredictability
by sdevlin 11y ago
> signed data include session id that is derived from result of first DH key exchange and thus unpredictable to either side of connection
The unpredictability of DH output depends on the group parameters and public key validation performed by the peer. If the group contains small subgroups, Eve can send an element of small order and predict the DH output with high probability.
For example, this is one of the attack vectors for the triple handshake attack on TLS: https://www.secure-resumption.com/tlsauth.pdf https://www.secure-resumption.com/tlsauth.pdf.
- dfox 11y agoWhich is mitigated in SSH by two things: 1) The DH group is negotiated by both peers from fixed list. 2) output of key exchange is hashed with various values that are not all controlled by same side of connection Also after reading the relevant part of RFC4253 I've found out that the session id is conceptually an output of key exchange, but in the DH case it's derived from contents of key exchange messages and not from the result itself (not that it makes much of an difference).