6 ms·
This sounds like another reason to no longer put SSH on the bare internet and layer security by only exposing wireguard and having sshd listen on the wireguard
by gxt 3y ago
This sounds like another reason to no longer put SSH on the bare internet and layer security by only exposing wireguard and having sshd listen on the wireguard network.
This is not helpful for currently vulnerable setups but hopefully will be a good reminder to think about defense in depth :)
- e40 3y agoHonest question: why would Wireguard be any safer?
- pvg 3y agoIt's a much more recent design that avoids this particular pitfall. This is mentioned in the tptacek's comment https://news.ycombinator.com/item?id=38684904 https://news.ycombinator.com/item?id=38684904
- pepoluan 3y agoAnd is there any guarantee that 20 years later a similar weakness of WireGuard will not be found?
- 3abiton 3y agoIt isolate the network? From my understanding the setup entails deploying sshd behind wireguard, thus only authenticated users can ssh.
- remram 3y agoWay fewer ciphers in the protocol, it basically has only one set of algorithms so there's way less negotiation.
- formerly_proven 3y agoYou can restrict most of these options both client- and server-side in SSH, which is basically always a winning move, regardless of protocol. You can't be downgraded to a protocol version or cipher that you've explicitly disabled.
- remram 3y agoYou can't select which ones get attention from the maintainers however.
- bux93 3y agoIf sshd is behind wireguard, it's defense in depth. The probability of an attacker targeting you having an exploit for both at the same time will be lower that having an exploit for either.
- pepoluan 3y agoOn the other hand, if the WireGuard implementation has a vulnerability, the attacker does not need to attack SSH at all and simply punch through WireGuard to have kernel-level access to the system. It's not defense-in-depth; it's a security chain : only as strong as its weakest link.