HappyScrappy
New member
don't know if you read slashdot, but there was a link to this article on the ssh hole (sort of) - slashdot mentions this being a problem with ssl as well, which I disagree with... well, with forms at least.
still better than plaintext I guess.
http://www.securityfocus.org/frames/?content=/templates/article.html?id=241
(basically just says that you can see via the rate at which things are coming in timewise and know that they are less likely to be certain keystroke pairs and more likely others and then it describe ways to prevent this measure progromatically in ssh - the have a paper on it as well that they are presenting at some show that I wasn't paying attention to)
(I think it is cool - I wouldn't mind being an engineer at qualcomm that is allowed to just try fun stuff out like this)
still better than plaintext I guess.
http://www.securityfocus.org/frames/?content=/templates/article.html?id=241
(basically just says that you can see via the rate at which things are coming in timewise and know that they are less likely to be certain keystroke pairs and more likely others and then it describe ways to prevent this measure progromatically in ssh - the have a paper on it as well that they are presenting at some show that I wasn't paying attention to)
(I think it is cool - I wouldn't mind being an engineer at qualcomm that is allowed to just try fun stuff out like this)