RE: [VulnDiscuss] Re: iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords

David Endler <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

I'll try to address some of the main points in this thread in just one
email, sorry in advance for the condensation.

>I do not think it makes much sense to say that applications that do not
>scrub memory are vulnerable, and those who do, are not, that's all.

>  3) The attacker gains physical access to the device - for example, the
>     workstation is stolen. He knows what to look for in the swap file
> and 
>     is hoping to find swapped out passwords.

>I agree that these issues are not vulnerabilities, however, I do think
>they are worth noting.  That is why we classify them as weaknesses.

>I think the point here is, if you have access to this memory.. You most
>likely, have access to do a lot more damage, and could probably gain the
>same information using multiple methods.

ok, I see that this comes down to semantics.  According to the popular
position (for scenario 3), no one disagrees that scrubbing passwords has
value, and yet the lack of this practice by itself does not constitute a
"vulnerability" since the real security issues reside in the design and
access levels of the OS memory management and are independent of the ssh
client.  Therefore, at best, everyone is still "vulnerable" to the same
issues, you've only mitigated one out of several possible attack vectors
(which is not a bad thing).  I can live with this description and the
label of "weakness" in this case.  I guess I'm not comfortable glossing
over a security design problem as a non issue simply because fixing it
doens't completely solve the problem, but only mitigates it slightly.  So
perhaps instead of vulnerable and not vulnerable which I concede is
misleading in the advisory, less susceptible and more susceptible?


>I don't deny there is a "problem", but i think at the point this becomes
>a problem, it's mostly null and void.
 
This is mostly a philosophical argument for fixing most "weaknesses". This
will always depend on the particular attack tree of potential exploits an
attacker will follow to get to what he wants.  Assuming he's good, then
fixing one of several weaknesses in software may just stall the
inevitable.  However, thwarting other less-skilled attackers and script
kiddies with these fixes is worth something I believe, rather than
dismissing them as non issues.

I think the topic has probably been beaten to death by now, I'd be glad to
continue this conversation further offline.

- -dave


-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0
Comment: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE4A96E4F

iQA/AwUBPjqOLUrdNYRLCswqEQLnlgCeISpXTQK50g42M5sfV9jTMxwbj+4AnjRZ
9X7tp11A4vxK1e3J42z2FISa
=vMjF
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.