3 ms·
Netgate is providing a pfsense patch that disables ETM MACs but leaves chacha20 enabled. The vuln announcement is arguably vague because of the way is uses "and
by notherhack 3y ago
Netgate is providing a pfsense patch that disables ETM MACs but leaves chacha20 enabled. The vuln announcement is arguably vague because of the way is uses "and" and "or" but from the vuln scanner source chacha20 is clearly not okay even without ETM.
https://forum.netgate.com/topic/184941/terrapin-ssh-attack
Shame they won't let me post a reply to let them know.
- Skrillor 3y agoYes, I commented this over at netgate as well. If you'd like to work around the vulnerability, you will need to disable both, chacha20-poly1305@openssh.com encryption and -etm@openssh.com MACs. Keeping either of them enabled still allows for exploitation.