PSA for bad OpenSSH bug: if you don't want any host you SSH to be able to get your **private** key, read this now: http://undeadly.org/cgi?action=article&sid=20160114142733 …
-
-
Replying to @patio11
You want to do this even if you only connect to servers you trust (today): you may eventually lose a server to the enemy and connect to it.
2 replies 16 retweets 9 likes -
Replying to @patio11
"Hey something's wrong with web47." "Hmm, let me SSH in. Oh it's rooted." *bam* You just lost every host you can SSH into w/ that keypair.
4 replies 34 retweets 19 likes
@patio11 For non-agent keys, Is the encrypted? plaintext? private key in RAM at the vulnerable point? Do we know?
12:08 PM - 14 Jan 2016
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.