4 ms·
> If you can't update a system, you have no business exposing it to a network. Full stop. What about isolated networks, a single Ethernet switch for example, u
by 127361 3y ago
> If you can't update a system, you have no business exposing it to a network. Full stop.
What about isolated networks, a single Ethernet switch for example, used for industrial automation? We can't keep replacing equipment every 5 years because they keep changing crypto protocols.
Many industrial networking protocols have no security at all. No encryption. Not even a password. They achieve their security by being disconnected from the outside world, constrained to a single room or building. If an attacker can get physical access to the wires, then we have a lot more to worry about than network security.
- xoa 3y agoIn this case though literally what are you even complaining about? If it's physically isolated so you don't need to update the old hardware, then you don't need to update OpenSSH either. Right? You can just leave whatever terminal you use right now on whatever it runs right now forever. That's the basic discontinuity here. The reason one would want to keep OpenSSH updated and continuing to receive development work is for use in a networked environment without full physical security from the world. If you have something stuck on DSA it shouldn't have any exposure to the world. So there's no problem here. At the very least one could softgap with old-ssh-in-VM that is completely restricted in what it can access.
- 127361 3y agoSorry, I likely screwed up my reasoning in that comment, I was under a lot of pressure at the time. The option to delete my post is gone, so I can't remove it.