Re: ARCFOUR and initialization vectors

In article <pan.2007.>,
K. Jennings <kjennings@xxxxxxxxxxxxxx> wrote:
How is the initialization vector contemplated in the SSH protocol
(both versions) used when the bulk encryption algorithm selected is
ARCFOUR? I thought that IVs do not apply to this streaming algorithm.

I don't know about SSH-1, but in SSH-2 (using "arcfour", "arcfour128",
or "arcfour256"), the IV generated by the key-generation algorithm
isn't used.

Ben Harris