“The Terrapin attack is a novel cryptographic attack targeting the integrity of the SSH protocol, the first-ever practical attack of its kind, and one of the very few attacks against SSH at all. The attack exploits weaknesses in the specification of SSH paired with widespread algorithms, namely ChaCha20-Poly1305 and CBC-EtM, to remove an arbitrary number of protected messages at the beginning of the secure channel, thus breaking integrity. In practice, the attack can be used to impede the negotiation of certain security-relevant protocol extensions. Moreover, Terrapin enables more advanced exploitation techniques when combined with particular implementation flaws, leading to a total loss of confidentiality and integrity in the worst case.”

“Although we suggest backward-compatible countermeasures to stop our attacks, we note that the security of the SSH protocol would benefit from a redesign from scratch, guided by all findings and insights from both practical and theoretical security analysis, in a similar manner as was done for TLS 1.3.”

  • 1984@lemmy.today
    link
    fedilink
    arrow-up
    0
    ·
    9 months ago

    Omg, they said “man in the middle” attack.

    Let’s rename it to “they in the middle” attack for fun.

    • Evkob@lemmy.ca
      link
      fedilink
      arrow-up
      0
      arrow-down
      1
      ·
      9 months ago

      I know nothing I say would stop you from being a fuckwit asshole, so I won’t even try, but if you’re going to be like this please at least know the difference between a noun and a pronoun.

      Your “joke” (which is really not a joke and just bigotry, really, but you seem like a lost cause so I won’t bother going on about it) doesn’t make sense because in no context would anyone say “they in the middle”. They/them are pronouns, typically for people who identify as non-binary. You’d say “non-binary person in the middle” or “enby in the middle”. Saying “they in the middle” is equivalent to “he in the middle”, not “man in the middle”.

      This is, of course, disregarding the fact that no one actually gives a fuck if you use the phrase “man in the middle”. I swear I see more dumbass “jokes” like this than actual attempts to use inclusive language. At this point, the transphobia is almost a secondary nuisance compared to the complete lack of any comedic skills.