Re: Ubuntu Loco Meeting 8/15/08 @ 8:00pm
"Matthew Bowie" <[email protected]>
| Newsgroups | gmane.org.user-groups.nmlug |
|---|---|
| Message-ID | <[email protected]> |
Did the OpenSSH issue actually affect you at all (other than having to check your systems)? I've checked my keys in use (most generated during the affected time period), and haven't found any blacklisted ones. I read on one article that the uninitialized buffer (the code for which was removed, causing this problem) was only used if /dev/urandom was not available at the time the key was generated. I haven't checked the source to verify this though, anyone have an informed answer about this? Has anyone on this list actually find a vulnerable key on any of their systems? I'm beginning to think it was a colossal screw-up from a technical and QA standpoint, but that it's not nearly as big a deal as the media/bloggers/etc are making it out to be (since /dev/urandom is available on a vast majority of systems, assuming the post I read was correct). Matt > We have lots to talk about tonight like all the fun the OpenSSH issue has > caused us.....hope to see you there. > > > > David Thomas > -- Matthew Bowie Programmer/IT Consultant [email protected] _______________________________________________ NMLUG mailing list [email protected] http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug