4 ms·
How does the default config of todays openssh hold up? Are these guidelines still important?
by rain1 8y ago
How does the default config of todays openssh hold up? Are these guidelines still important?
- computerfriend 8y agoSome things have improved. But yes, they're still important.
- lvh 8y agoCan you elaborate? A lot of the reasons in the article are weak at best; such as the timing attack/off-curve attack FUD for NIST curves. There are a handful of good things in here (I commented elsewhere with a list), but nobody should be setting ciphersuites in their ssh config.
- computerfriend 8y agoI'm not so sure. Yes, ideally that wouldn't be the case. But there are still weak ciphersuits available by default. (SP 800-63B isn't really relevant to whether NIST curves are safe or not.) Another benefit is the SSH logs now fill up with cipher negotiation errors instead of failed authentication attempts, which stops automated "attacks" quicker and makes for cleaner logs if trying to parse for meaningful authentication attempts.