Packet Timing and Data Leaks

Peter Stuge peter at stuge.se
Thu Aug 10 20:42:06 AEST 2023


Philipp Marek wrote:
> An easy workaround is to use a password manager (a plain file as a minimum)

If you can/want to use a file then consider using a key instead.

publickey authentication is non-interactive on the wire and the key is
already unlocked so packet timing leaks nothing about your passphrase.


//Peter


More information about the openssh-unix-dev mailing list