Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: rarestia
OpenSSH generates private keys for a hash and discards them, if I’m not mistaken. The problem with this vulnerability is that private keys can be compromised, thus making encryption worthless.

Good to know. Yeah, the keys are regenerated, but they have a lifespan. I'm showing a default regeneration interval of 1H on my system, and that's about what I remember from looking at it in the past, so it's not that bad. The more I read on this, it sounds like the attack vector on this is such that it is likely the surface are of ssh is pretty small, if it exists at all. That makes me happy, but doesn't completely dispell my inborn paranoia. :-) I expect to see new ssh binaries in the pipeline soon enough. The folks who maintain ssh are pretty paranoid as well, so they'll likely take a close look at the fix first to make sure it doesn't break anything else. SSH is a critical utility.

30 posted on 04/09/2014 12:08:05 PM PDT by zeugma (Don't cry because it's over, smile because it happened - Dr. Seuss (I'll see you again someday Hope))
[ Post Reply | Private Reply | To 27 | View Replies ]


To: zeugma

I only use the CLI for OpenSSH to generate login keys for my jump servers. This allows me to turn off password-based authentication and use certificates only. That reduces the chance of a successful brute force attack manifold.


31 posted on 04/10/2014 8:08:46 AM PDT by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 30 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson