Hooray! I knew about this before you did! How do you like that, Mr so-called paranoid crypto freak?
[Anyway, IIRC it's not that difficult to harden against this kind of attack - sending a few NOOPs in the right place so you always send 256 chars of password or whatever. I believe a modified client can do this talking to an unmodified sshd. And I've been using plaintext VNC quite a bit recently, as well as pserver CVS, neither of which are great security. Fuck it.]
Ha!
Date: 2001-08-22 12:24 pm (UTC)[Anyway, IIRC it's not that difficult to harden against this kind of attack - sending a few NOOPs in the right place so you always send 256 chars of password or whatever. I believe a modified client can do this talking to an unmodified sshd. And I've been using plaintext VNC quite a bit recently, as well as pserver CVS, neither of which are great security. Fuck it.]