3 ms·
For two years there was an undiscovered Debian-specific vulnerability in their OpenSSL package borking the generation of keys. But your point about being screwe
by napkin 3y ago
For two years there was an undiscovered Debian-specific vulnerability in their OpenSSL package borking the generation of keys. But your point about being screwed from within applies to this case- regenerating the keys on an affected system would not have solved the problem, until it was patched. For those curious, look up ssh-vulnkey.
- mkj 3y agoFollowing the guide's steps wouldn't have helped in the Debian case. I reckon on average a distro ssh maintainer is more aware than an average end user following a hardening guide, even with mistakes like that one.