> This attempts to hide inter-keystroke timings by sending interactive traffic at fixed intervals (default: every 20ms) when there is only a small amount of data being sent. It also sends fake "chaff" keystrokes for a random interval after the last real keystroke. These are controlled by a new ssh_config ObscureKeystrokeTiming keyword. So does it send these phantom keystrokes only when there are real keystrokes? On f…
It's 2023, you shouldn't be using the old rsa keys anyway.
I'd say at this point the risk of silly goofs in the curve code is similar to the risk from RSA given how well understood it is.