They talk about FreeBSD in the original article and the guy tests that on other OS and say it's not a serious vuln?
Mr Hansteen is saying it is not a serious OpenSSH vuln, like the tech media is claiming it is.
This is a serious vuln for FreeBSD. Period.
That's why the original disclosure and subsequent news articles clearly stated it was a FreeBSD and/or PAM vulnerability, and didn't run with headlines such as "OpenSSH keyboard-interactive authentication brute force vulnerability"[0] or "Bug in widely used OpenSSH opens servers to password cracking"[1].
Comments
They talk about FreeBSD in the original article and the guy tests that on other OS and say it's not a serious vuln?
This is a serious vuln for FreeBSD. Period.
Mr Hansteen is saying it is not a serious OpenSSH vuln, like the tech media is claiming it is.
That's why the original disclosure and subsequent news articles clearly stated it was a FreeBSD and/or PAM vulnerability, and didn't run with headlines such as "OpenSSH keyboard-interactive authentication brute force vulnerability"[0] or "Bug in widely used OpenSSH opens servers to password cracking"[1].
[0] https://kingcope.wordpress.com/2015/07/16/openssh-keyboard-i...
[1] http://arstechnica.com/security/2015/07/bug-in-widely-used-o...