|
|
|
|
|
by santaragolabs
2760 days ago
|
|
Man, this paper is a classic. I love traffic analysis attacks like this. I did something myself six years back albeit with a somewhat contrived example figuring out what someone is looking at on Google Maps via request and response sizes. Example video here https://www.youtube.com/watch?v=skQNwd9Jij4 and https://ioactive.com/ssl-traffic-analysis-on-google-maps/. I am speculating that nice traffic analysis attacks can be done on mosh (which is a great tool btw) to, similar to the paper that is in this thread. It's been sort of on my "todo/research" list but haven't been able to sit down for a few days and mess around with it. And I'm sure that QUIC (HTTP/3) will open up some interesting avenues of attack here too. |
|
Certainly I've had 'ssh -C' in finger-memory even on LANs for well over a decade.