New SSH Vulnerability - Schneier on Security (www.schneier.com)
from IllNess@infosec.pub to securitynews@infosec.pub on 16 Nov 2023 00:16
https://infosec.pub/post/4944782

#securitynews

threaded - newest

MrPoopyButthole@lemmy.world on 16 Nov 2023 06:20 collapse

The countermeasure to the attacks we describe in this paper is well known: implementations should validate signatures before sending them. OpenSSH, the most common SSH implementation we observed in this data, implements this countermeasure because it uses OpenSSL to generate signatures, and OpenSSL has included countermeasures against RSA fault attacks since 2001.