[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-Disclosure] new ssh exploit?



2003-09-16T11:25:47 Ron DuFresne:
> On Mon, 15 Sep 2003, christopher neitzert wrote:
> > 1. upgrade to lsh.
>
> But, one has to remember ssh does not stand alone, at least openssh, it
> needs openssl to be properly maintained as well.

Another incentive to ditch openssh altogether. lsh seems to work
fine. At last.

lsh doesn't use openssl. It is a completely different code base from
the other sshes.

It's ssh v2 only; I think that's a transition whose time has come.

-Bennett

Attachment: pgp00028.pgp
Description: PGP signature