• lemmyvore
    link
    fedilink
    English
    8111 months ago

    Only affects RSA keys, and then only 1 in a million keys are vulnerable. So this is mostly of academic (rather than practical) interest, but nevertheless it will lead to further hardening of the SSH protocol which is nice.

    • @PlasticExistence
      link
      English
      2511 months ago

      It also appears to only affect non-OpenSSH secure shell implementations.

    • @deafboy
      link
      English
      111 months ago

      Security of a sufficiently long RSA key was the one true constant in my life. Poof… There it goes!

      Once attackers have possession of the secret key through passive observation of traffic, they can mount an active Mallory-in-the-middle

      Mallory in the middle would be a sick punkrock band name though.