6 ms·
> Otherwise, you will miss out on better ciphers as they are added and would be stuck on this one forever. You’ve identified issues with whitelisting but black
by nominated1 7y ago
> Otherwise, you will miss out on better ciphers as they are added and would be stuck on this one forever.
You’ve identified issues with whitelisting but blacklisting isn’t perfect either. For example, many don’t trust NIST and may want to prevent the use of any of their future curves. Blacklisting fails here.
When updating to a newer version of SSH I think it’s good practice to ‘man ssh_config’ and at least look at KexAlgorithms, HostKeyAlgorithms and Ciphers.