Settings

Theme

Cryptographic keys protecting SSH connections stolen in new attack – ArsTechnica

arstechnica.com

61 points by mkolassa · 4 comments

Reader

3 threads
oxygen_crisis

Previous discussion:

Passive SSH Key Compromise via Lattices [pdf] (iacr.org)

https://news.ycombinator.com/item?id=38161174

bebop404

In certain closed-source implementations.

>"The researchers traced the keys they compromised to devices that used custom, closed-source SSH implementations that didn’t implement the countermeasures found in OpenSSH and other widely used open source code libraries. The devices came from four manufacturers: Cisco, Zyxel, Hillstone Networks, and Mocana. Both Cisco and Zyxel responded to the researchers’ notification of the test results before the completion of the study. Hillstone responded afterward."

nier

Excerpt from the linked article: «It affects only keys using the RSA cryptographic algorithm, […].»

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection