Re: Ubuntu Loco Meeting 8/15/08 @ 8:00pm

"Matthew Bowie" <[email protected]>
Newsgroups gmane.org.user-groups.nmlug
Message-ID <[email protected]>
Did the OpenSSH issue actually affect you at all (other than having to
check your systems)?  I've checked my keys in use (most generated
during the affected time period), and haven't found any blacklisted
ones.  I read on one article that the uninitialized buffer (the code
for which was removed, causing this problem) was only used if
/dev/urandom was not available at the time the key was generated.  I
haven't checked the source to verify this though, anyone have an
informed answer about this?

Has anyone on this list actually find a vulnerable key on any of their
systems?  I'm beginning to think it was a colossal screw-up from a
technical and QA standpoint, but that it's not nearly as big a deal as
the media/bloggers/etc are making it out to be (since /dev/urandom is
available on a vast majority of systems, assuming the post I read was
correct).

Matt

> We have lots to talk about tonight like all the fun the OpenSSH issue has
> caused us.....hope to see you there.
>
>
>
> David Thomas
>
-- 
Matthew Bowie
Programmer/IT Consultant
[email protected]
_______________________________________________
NMLUG mailing list
[email protected]
http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.