Subject: Re: "ssh" with SSHv2 public key buggy?
To: Dave Huang <khym@azeotrope.org>
From: Perry E. Metzger <perry@wasabisystems.com>
List: netbsd-users
Date: 10/09/2001 16:30:02
Dave Huang <khym@azeotrope.org> writes:
> On 9 Oct 2001, Perry E. Metzger wrote:
> > > could you say more?
> >
> > I think that's pretty explicit, isn't it?
>
> Being explicit isn't the same as saying more.
The protocol has about twenty holes in it, including the fact that it
doesn't use real MACs on the data being passed. If you want to learn
more on the subject, there is plenty already written that you can find
in things like ssh mailing list archives.
.pm
--
Perry E. Metzger perry@wasabisystems.com
--
NetBSD Development, Support & CDs. http://www.wasabisystems.com/