Skip to content

EncryptionMethod : Plain ? what protocol is implementing AEAD like? #331

Description

@jlmxyz

just wondering what protocol could use the plain mode?

openvpn : since the packet structure is identifiable with DPI, I think it won't work in Plain....
ssh : only the handshake can be identified with DPI (it seems)

to avoid overhead encrypt over encrypt I wonder if it would be possible to encrypt partially (temporal or packet parts) to only hide the parts that are "DPI" weak

  • for SSH only encrypt the handshake and a few (configurable) following packets then transmit plain (a "encrypted packet count" parameter in config or "encrypted reply count" or "encrypted time duration" (think it's less safe, since depend of the connection lag...) )
  • for openvpn encrypt partially the packets (a "packet partial encryption offset and size" parameter in config) although openvpn tls-crypt would do (it seems) to allow use of plain?

best regards.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions