Settings

Theme

Cryptographic keys protecting SSH connections stolen in new attack – ArsTechnica

arstechnica.com

61 points by mkolassa 2 years ago · 4 comments

Reader

oxygen_crisis 2 years ago

Previous discussion:

Passive SSH Key Compromise via Lattices [pdf] (iacr.org)

https://news.ycombinator.com/item?id=38161174

bebop404 2 years ago

In certain closed-source implementations.

>"The researchers traced the keys they compromised to devices that used custom, closed-source SSH implementations that didn’t implement the countermeasures found in OpenSSH and other widely used open source code libraries. The devices came from four manufacturers: Cisco, Zyxel, Hillstone Networks, and Mocana. Both Cisco and Zyxel responded to the researchers’ notification of the test results before the completion of the study. Hillstone responded afterward."

nier 2 years ago

Excerpt from the linked article: «It affects only keys using the RSA cryptographic algorithm, […].»

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection