Bug#1001335:

2021-12-09 Thread Hans-Christoph Steiner
Great to hear that pipelining is already in use! I guess HTTPS plus pipelining could mean that file size is no longer reliably readable for the network observer. I've never profiles TLS and pipelining to know if there are still visible signatures that would let the network observer find the bo

Bug#1001335: apt should use TLSv1.3 Record Padding to obscure file size metadata

2021-12-08 Thread Julian Andres Klode
On Wed, Dec 08, 2021 at 09:44:19PM +0100, Hans-Christoph Steiner wrote: > > Package: apt > Version: 2.3.13 > Severity: wishlist > > apt should pad its TLS connections to obscure the size of the downloaded > files from network observers. Right now, an attacker could build an index > of all packag

Bug#1001335: apt should use TLSv1.3 Record Padding to obscure file size metadata

2021-12-08 Thread Hans-Christoph Steiner
Package: apt Version: 2.3.13 Severity: wishlist apt should pad its TLS connections to obscure the size of the downloaded files from network observers. Right now, an attacker could build an index of all package sizes, then track the size of HTTPS streams to Debian mirrors, and from that, be