Linked by Thom Holwerda on Wed 15th Apr 2009 09:54 UTC
Thread beginning with comment 358652
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
News
Linked by Thom Holwerda on 05/21/13 22:06 UTC
Linked by Thom Holwerda on 05/21/13 21:45 UTC
Linked by Thom Holwerda on 05/21/13 15:53 UTC
Linked by Thom Holwerda on 05/20/13 22:43 UTC
Linked by Thom Holwerda on 05/20/13 21:50 UTC
Linked by Thom Holwerda on 05/19/13 23:15 UTC
Linked by Thom Holwerda on 05/19/13 23:11 UTC, submitted by Drumhellar
Linked by Thom Holwerda on 05/18/13 21:06 UTC
Linked by Thom Holwerda on 05/18/13 7:37 UTC
Linked by fran on 05/18/13 1:38 UTC
More News »
Sponsored Links



Member since:
2009-04-15
This is not true. It was not a SSH vulerability but a problem in OpenSSL which therefore *also* influenced OpenSSH. Here is a link: http://www.metasploit.com/users/hdm/tools/debian-openssl/
All the entropy besides the PIDs (and even those are mainly predictable) was thrown out of OpenSSL. To quote an article from "2600" (Volume Twenty-Five, Number Two, Page 52f) that is 1.9 x 10^-32 less keys than before (0.0 thirty-one zeros, 19). To put it in other figures all the remaining hashs (for one hardware plattform) took now 40MB of space instead of 3.7 x 10^32 gigabyte.
But don't get me wrong I use UNIX-like operating systems and Debian is by far my favorite Linux distribution, even after this incident.