Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

SSH isn't out of scope for your attacker. If it's out of your scope as a defender, that's a problem.

That's why this is hard. You don't get to control what channels of information the attacker looks at.



I'm not sure how attacking SSH would help you crack a web app (the users in the app won't be unix accounts), but I'll take your word for it :)


If the web app uses extra memory or CPU, SSH response time may be affected. So delaying in the web app doesn't do a good job of concealing CPU and memory use by the web app, because it's a shared-resource system.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: