Subject: Re: Proposal: Disable SSHd Protocol v1 by Default (WAS: Re: ssh
To: , <netbsd-users@netbsd.org>
From: Greg A. Woods <woods@weird.com>
List: netbsd-users
Date: 03/15/2002 01:51:47
[ On Friday, March 15, 2002 at 11:35:30 (+0900), Curt Sampson wrote: ]
> Subject: Re: Proposal: Disable SSHd Protocol v1 by Default (WAS: Re: ssh  config path change (/etc -> /etc/ssh)) 
>
> Ok, I'm still unclear as to exactly what advantage V2 has over V1,
> besides that CRC insertion attack. (Not that that isn't good enough
> reason to switch to V2.)

There are several very important non-security related advantages, not
the least of which is that it's likely to be close to what the IETF
eventually publish.

However for me the ability to support working flow control is the
biggest benefit and I would have switched even if there had been no
security issues with the first version of the protocol or its
implementation(s).  I've wanted working flow control in SSH since before
SSH was widely used!

-- 
								Greg A. Woods

+1 416 218-0098;  <gwoods@acm.org>;  <g.a.woods@ieee.org>;  <woods@robohack.ca>
Planix, Inc. <woods@planix.com>; VE3TCP; Secrets of the Weird <woods@weird.com>