Proper analysis of the OpenSSH vuln: https://www.qualys.com/2016/01/14/cve-2016-0777-cve-2016-0778/openssh-cve-2016-0777-cve-2016-0778.txt … TL;DR agent keys safe, non-agent keys only leak encrypted, MITM not possible.
-
-
Replying to @flameeyes
@flameeyes Pretty much. If you see "connection suspended, press return to resume", hit ^C and the atack is prevented. It even warns you.2 replies 0 retweets 0 likes
@flameeyes I mean, you could use this to jump between servers that use automated SSH (e.g. I have systems like that), but other than that...
12:46 PM - 14 Jan 2016
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.