Skip to content

Comment on US Emergency Alert System private SSH key mistakenly distributed

Comments

FTA: Stations that use vulnerable gear should upgrade to version 2.0-2, which is available by sending an e-mail to suport@digitalalertsystems.com.

As a "broadcast-emitting-messages-company" admin: would I really upgrade a system, which functionalities include complete take-over of my broadcast equipment, that is vulnerable to someone mistaking the private and public ssh keys of his "taking-over-any-equipment" equipment ?

I'd rather un-subscribe from that "service" in the limit of legality until that point of failure is fixed.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.