thewayne: (Default)
[personal profile] thewayne
This is very bad.

SSH is one of the fundamental underpinnings that makes the internet and world wide web fundamentally secure. Well, we now know that it has some serious weaknesses.

What it boils down to is compatibility. There's lots of ways to implement SSH. Think of them as a whole bunch of switches, and each switch is a different implementation. Some are strong, some are not. They're all out there so that if I use Switch A and you use Switch B, we can still talk. Very convenient, but also a bit problematic. What happens if Switch C has some weaknesses to it?

The problem is that in lots of SSH implementations, Switch C is left turned on for ease of compatibility. And unless people know and specifically turn Switch C off, and all the other known weak switches off, then there are exploitable weaknesses.

The bad news? LOTS of systems are vulnerable. From the article: "A scan performed by the researchers found that 77 percent of SSH servers exposed to the Internet support at least one of the vulnerable encryption modes, while 57 percent of them list a vulnerable encryption mode as the preferred choice."

77% support the vulnerable mode and 57% PREFERRED IT? YIKES!

The good news is that it requires a Man In The Middle attack (MITMs), and those are not easy to carry out - but they can be done. The even better news is that the security researchers have released a scanner to let server administrators know if they are vulnerable. Some SSH packages have been patched to fix this issue, others I'm sure are in process. But there is also a likelihood that some implementations are not, or that some servers are not being updated for various reasons and will continue to be vulnerable.

I don't think this represents much of a problem for users, so much as for network administrators. Unless you're a very valuable person and likely to be targeted by hackers or world powers, you're not likely to have the resources to pull this off moved against you. As I said, MITMs are not easy to pull off, and if you're not Pentagon R&D level sort of stuff, you're probably safe. But I expect Apple and Microsoft and the various Linux distros will be patching their SSH bundles to make sure everything is good in the very near future, just to make sure.

Warning about the article: it gets REALLY deep into the SSH weeds, so don't bother with it if you're not already wise into the subject.

https://arstechnica.com/security/2023/12/hackers-can-break-ssh-channel-integrity-using-novel-data-corruption-attack/

Date: 2023-12-20 04:07 pm (UTC)
arlie: (Default)
From: [personal profile] arlie
Here we go again. I vaguely remember a month some years ago, when there were multiple security fixes in ssh (probably openssh), and a friend and colleague was kept busy integrating upstream patches into a FreeBSD-based networking product. It appeared that once researchers focussed on it, they found a lot of issues. IIRC, that was just before the year of the repeated patches to ntpd - who'd have thought that a time sync protocol would accidentally allow denial-of-service attacks? (That one kept me busy applying patches.)

Date: 2023-12-20 08:31 pm (UTC)
silveradept: A kodama with a trombone. The trombone is playing music, even though it is held in a rest position (Default)
From: [personal profile] silveradept
This is why it's best to disclose and to work on things that can have their source changed and their implementations shifted. There will probably be updated packages for most distributions pretty quickly to disable the vulnerable methods, and then later patches will probably help harden systems more against attacks of that family.

Date: 2023-12-21 05:57 am (UTC)
disneydream06: (Disney Scared)
From: [personal profile] disneydream06
Not surprisingly, I don't have a clue what any of that is about. :o
Hugs, Jon

Date: 2023-12-21 07:01 am (UTC)
disneydream06: (Disney Alice Question Mark)
From: [personal profile] disneydream06
So what do you wanna know about the hospital? LOL!!!!!!!!!!!!!!!!!

Date: 2023-12-22 12:46 am (UTC)
disneydream06: (Disney Scared)
From: [personal profile] disneydream06
Holy Crap, I don't blame you. :o

Date: 2023-12-26 03:29 am (UTC)
kellan_the_tabby: My face, reflected in a round mirror I'm holding up; the rest of the image is the side of my head, hair shorn short. (Default)
From: [personal profile] kellan_the_tabby
I usually run updates at the beginning of the month, but under the circumstances ...

... yep, there's a tidy pile of SSH stuff waiting there.

Date: 2023-12-27 02:23 am (UTC)
kellan_the_tabby: My face, reflected in a round mirror I'm holding up; the rest of the image is the side of my head, hair shorn short. (Default)
From: [personal profile] kellan_the_tabby
I love running Linux.

June 2025

S M T W T F S
123456 7
8910 11121314
15 1617 18 1920 21
22232425262728
2930     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jun. 26th, 2025 11:22 pm
Powered by Dreamwidth Studios