Re: Patching a SSH 'Weakness'

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: johan beisser <jb@...>
Cc: <misc@...>
Date: Friday, September 12, 2008 - 9:41 pm

On Fri, Sep 12, 2008 at 05:42:08PM -0700, johan beisser wrote:

Was it you who said earlier that you weren't a cryptanalyst? Well,
neither am I, but I have come away with one lesson from them: be on the
attack. You are on the defense, and always putting forward reasons why
this isn't a quick total penetration. Instead, try thinking of what
information you can get by snooping, and what you might do with it. It's
a whole different mindset. You can see this in Damien Miller's messages.
Rather than pooh-pooh this like you, he's considering the problems and
trying to think of ways to break openssh. This attitude of Damien (and
other obsd devs) is why openssh is so strong. If they thought only of
defense then openssh would have a track record similar to so many other
programs.

Back when I did financial software we played a game of thinking of ways
to steal money. We found several ways and plugged those holes, and
related holes. Most of the holes were never tried but some of them were
(and people went to prison). If we had not played our game we *never*
would have found some of the holes.

You should try this game. Not only can it be rewarding for your own
security, it can be fun as well.

--
Darrin Chandler | Phoenix BSD User Group | MetaBUG
dwchandler@stilyagin.com | http://phxbug.org/ | http://metabug.org/
http://www.stilyagin.com/ | Daemons in the Desert | Global BUG
Federation

[demime 1.01d removed an attachment of type application/pgp-signature]

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: Patching a SSH 'Weakness', Stuart Henderson, (Fri Sep 12, 4:16 pm)
Re: Patching a SSH 'Weakness', johan beisser, (Fri Sep 12, 5:05 pm)
Re: Patching a SSH 'Weakness', Philip Guenther, (Fri Sep 12, 6:12 pm)
Re: Patching a SSH 'Weakness', johan beisser, (Fri Sep 12, 6:34 pm)
Re: Patching a SSH 'Weakness', Damien Miller, (Fri Sep 12, 7:08 pm)
Re: Patching a SSH 'Weakness', johan beisser, (Fri Sep 12, 8:42 pm)
Re: Patching a SSH 'Weakness', Toni Spets, (Sat Sep 13, 6:21 am)
Re: Patching a SSH 'Weakness', johan beisser, (Sat Sep 13, 3:51 pm)
Re: Patching a SSH 'Weakness', Darrin Chandler, (Fri Sep 12, 9:41 pm)
Re: Patching a SSH 'Weakness', johan beisser, (Fri Sep 12, 10:46 pm)
Re: Patching a SSH 'Weakness', Nikola Knežević, (Mon Sep 15, 10:03 am)
Re: Patching a SSH 'Weakness', Darrin Chandler, (Sat Sep 13, 12:43 am)
Re: Patching a SSH 'Weakness', johan beisser, (Sat Sep 13, 2:24 am)
Re: Patching a SSH 'Weakness', Stuart Henderson, (Fri Sep 12, 5:28 pm)
Re: Patching a SSH 'Weakness', johan beisser, (Fri Sep 12, 5:50 pm)
Re: Patching a SSH 'Weakness', johan beisser, (Fri Sep 12, 5:37 pm)
Re: Patching a SSH 'Weakness', Marti Martinez, (Fri Sep 12, 4:59 pm)
Re: Patching a SSH 'Weakness', Stuart Henderson, (Fri Sep 12, 5:19 pm)
Re: Patching a SSH 'Weakness', Jonathan Schleifer, (Sat Sep 13, 3:24 am)