Slashdot Mirror


SSH Vulnerability and the Future of SSL

iamchris writes "Growing complacent in regards to security is dangerous. I've become more and more dependant on the SSL-type tools for my security... ssh itself, ssl for my web content, scp, sftp, etc... We all know nothing is 100% secure (or if you don't, God help you). An article on Security Focus cites a vulnerability with SSH and passwords. We usually type them in letter-by-letter. A lot of information can be gleaned from the timing of the keystrokes and some (relatively simple) packet decoding. Is there a better alternative to SSL based tools (Perhaps TLS)? Is there anything that can be done with the clients help with the small packet issue?"

6 of 290 comments (clear)

  1. Root by Strom+Thurmond+(R-SC · · Score: -1, Offtopic

    I got it.

    --

    Strom Thurmond; the dean of the US Senate...
    the deadest fart on slashdot.

  2. fp by dogas · · Score: -1, Offtopic

    damn!

    --
    'When the going gets weird, the weird turn pro.' -HST
  3. Relevent link by Anonymous Coward · · Score: -1, Offtopic
    1. Re:Relevent link by Anonymous Coward · · Score: -1, Offtopic

      pure genius...

  4. Sad news - Stepehn King dead at 54 by Anonymous Coward · · Score: -1, Offtopic


    I just heard sad news on talk radio -Horror/fiction writer Stephen King was found dead in his Maine house this morning. I'm sure we'll all miss him - even if you didn't read his books you've probably enjoyed one of his movies. Truly an American icon.

  5. Sad news - Nietzsche dead at 167 by Anonymous Coward · · Score: -1, Offtopic

    I just heard sad news on talk radio -philosophy writer Nietzsche was found dead in his house in Weimar
    this morning. I'm sure we'll all miss him - even if you didn't read his books you've probably enjoyed one of
    his movies. Truly a philosophy icon.