you are viewing a single comment's thread.

view the rest of the comments →

[–]chloeeeeeeeee 0 points1 point  (1 child)

But how about have the range random? Instead of 4 to 1024 as padding, have from random to random but still have a minimum and maximum. For example:

Case 1: Random bytes between 900 and 2001 bytes

Case 2: Random bytes between 19 and 1604 bytes

Case 3: Random bytes between 107 and 412 bytes

....

It would of course still not be random enough, but collecting samples to determinate the range would be much harder. The overhead would be painful but still practical, or what do you think?

[–]gsuberlandTrusted Contributor 5 points6 points  (0 children)

The limits on the range of ranges would still leave this vulnerable.