Skip to content

Comment on The OpenSSH Bug That Wasn'tparent

Comments

They talk about FreeBSD in the original article and the guy tests that on other OS and say it's not a serious vuln?

Mr Hansteen is saying it is not a serious OpenSSH vuln, like the tech media is claiming it is.

This is a serious vuln for FreeBSD. Period.

That's why the original disclosure and subsequent news articles clearly stated it was a FreeBSD and/or PAM vulnerability, and didn't run with headlines such as "OpenSSH keyboard-interactive authentication brute force vulnerability"[0] or "Bug in widely used OpenSSH opens servers to password cracking"[1].

[0] https://kingcope.wordpress.com/2015/07/16/openssh-keyboard-i...

[1] http://arstechnica.com/security/2015/07/bug-in-widely-used-o...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.