4 ms·
> If you need ammunition to encourage your corporate IT to allow you to run the proper ssh-agent service to do your job instead of increasing your attack surfac
by gred 2y ago
> If you need ammunition to encourage your corporate IT to allow you to run the proper ssh-agent service to do your job instead of increasing your attack surface by installing PuTTY/Pageant, you could collect a list of vulnerabilities such as the one posted here...
This made me laugh :-) Grandparent is probably happy to just fly under the radar. The suggested conversation would probably play out thusly:
> IT! You idiots! Your dumb policies are forcing me to use this insecure software! Look how many vulnerabilities it has had over the years!
>> Hold up. Rewind. What's this software that you've installed?
> It's called PuTTY. And if you just change this policy I could...
>> And how insecure is it?
> Just check out all these vulnerabilities! It's probably not worse than the average, but it's unnecessary extra attack surface area that...
>> I'm going to need you to uninstall that. Now. And I'll need confirmation via email that you have done so by EOB, with your boss and the CISO on CC.
> But if you just change this boneheaded policy...
>> Now, please. We have a security incident on our hands. We can discuss policy another time. Is there anything else installed on your laptop that I should be aware of?
- chasil 2y agoActually, the corporate software repository is still pushing 0.67 or so. I need newer PuTTY to have a capable agent.
- richardwhiuk 2y agoSo the rationale you can't move to Windows SSH is because you can't run ssh-agent, but you can't run a useful version anyway?
- chasil 2y agoI have my own copy of putty, which I use in preference to what is offered by corporate. I upgraded it to 0.81 today.