3 ms·
"If You're Typing The Letters A-E-S Into Your Code, You're Doing It Wrong" still applies, even though we now type chacha20. https://people.eecs.berkeley.edu/~da
by kangaroopouch 5y ago
"If You're Typing The Letters A-E-S Into Your Code, You're Doing It Wrong" still applies, even though we now type chacha20. https://people.eecs.berkeley.edu/~daw/teaching/cs261-f12/misc/if.html https://people.eecs.berkeley.edu/~daw/teaching/cs261-f12/mis...
We should aim for not having to fiddle with SSH config, and having sane defaults.
That could involve:
* cryptographers advocating changing OpenSSH defaults
* people refining their threat model to being able to accept weaker defaults
* Distributions or config management solutions that improve on the defaults in a careful considered way.
I use NixOS which generates my sshd_config. By default, NixOS:
* Disables root login via password: https://github.com/NixOS/nixpkgs/blob/8605fbd737e526c40ff8f01219db42b5d0076e23/nixos/modules/services/networking/ssh/sshd.nix#L148 https://github.com/NixOS/nixpkgs/blob/8605fbd737e526c40ff8f0...
* Sets ciphers according to Mozilla's recommendations: https://github.com/NixOS/nixpkgs/blob/8605fbd737e526c40ff8f01219db42b5d0076e23/nixos/modules/services/networking/ssh/sshd.nix#L312 https://github.com/NixOS/nixpkgs/blob/8605fbd737e526c40ff8f0...
Other distros, cfgmgmt, and container systems could do this too.