Berkeley CSUA MOTD:Entry 20875
Berkeley CSUA MOTD
 
WIKI | FAQ | Tech FAQ
http://csua.com/feed/
2025/07/09 [General] UID:1000 Activity:popular
7/9     

2001/3/21-22 [Computer/SW/Security] UID:20875 Activity:low
3/20                            \_ what about the broken sshd?  -tom
                              \_ Its not broken. It works fine for SSHv1
                                 and OpenSSH clients. Get a different client.
                                \_ what would you call a server that violates
                                   protocols?  I would call it broken.  The
                                   fact that openssh clients also violate
                                   protocols doesn't make the server any
                                   less broken.  And, once again, there's
                                   ABSOLUTELY NO ADVANTAGE TO USING OPENSSH.
                                    -tom
                                    \_ Totally there is!  Open source!
                                    \_ Why don't we run both versions? Run
                                       the non-OpenSSH version of port 69
                                       so that tom will shutup.
                                   \_ Uh, its free and it comes preinstalled
                                      with *BSD, MacOS X, Linux, etc.
                                      WTF would I want to download something
                                      extra from http://ssh.com that isn't nearly
                                      as well audited as OpenSSH and isn't
                                      free for corporate users?
                                        \_ what difference does it make
                                           whether it's free for corporate
                                           users?  You would want to download
                                           it because IT SUPPORTS MORE CLIENTS.
                                           Are you really this stupid?  -tom
                                           \_ Because some of us are corporate
                                              users, not gub'ment 'ployees.
                                                \_ we're not talking about what
                                                   you install in your cube.
                                                   you can connect to soda
                                                   if it's not running openssh.
                                                     -tom
                    http://ssh.com's ssh server doesn't like _/
                    OpenSSH clients and it doesn't like
                    NiftyTelnet SSH on the mac (ie it will
                    randomly drop my connection and scp
                    doesn't work right), both of
                    which currently work with soda's
                    OpenSSH server. No reason to switch
                    since switching would reduce the
                    number of clients that are supported.
                        \_ Bullshit.  I am using both openssh clients and
                           NiftyTelnet with http://ssh.com's server and they work
                           fine.  -tom
                                   \_ since you clearly are not making any
                                      progress getting the powers that be to
                                      switch from OpenSSH, why don't you
                                      harass the OpenSSH people and get them
                                      to fix it?
                                   \_ So, you like the added bloat of having
                                      to start the ssh1 daemon every time an
                                      ssh1 client connects? Once OpenSSH
                                      supports shession rekeying (promissed in
                                      the next major release) there will be
                                      no reason not to use OpenSSH.
2025/07/09 [General] UID:1000 Activity:popular
7/9     

You may also be interested in these entries...
2012/8/26-11/7 [Computer/SW/Security] UID:54465 Activity:nil
8/26    Poll: how many of you pub/priv key users: 1) use private keys that
        are not password protected 2) password protect your private keys
        but don't use ssh-agent 3) use ssh-agent:
        1) .
        2) ..
        3) ...
	...
2012/8/7-10/17 [Computer/SW/Security] UID:54455 Activity:nil
8/6     Amazon and Apple have lame security policies:
        http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/all
        "First you call Amazon and tell them you are the account holder, and
         want to add a credit card number to the account. All you need is the
         name on the account, an associated e-mail address, and the billing
         address. "
	...
2012/7/18-8/19 [Health/Men, Computer/SW/Security] UID:54438 Activity:nil
7/18    "Largest penis record holder arouses security suspicions at airport"
        http://www.csua.org/u/x2f (in.news.yahoo.com)
        \_ I often have that same problem.
        \_ I think the headline writer had some fun with that one.
           \_ One time when I glanced over a Yahoo News headline "U.S. busts
              largest-ever identity theft ring" all I saw was "U.S. busts
	...
2012/4/23-6/1 [Computer/SW/WWW/Browsers] UID:54360 Activity:nil
4/19    My Firefox 3.6.28 pops up a Software Update box that reads "Your
        version of Firefox will soon be vulnerable to online attacks."  Are
        they planning to turn off some security feature in my version of
        Firefox?
        \_ Not as such, no, but they're no longer developing this version,
           so if a 3.6.x-targeted hack shows up, you're not going to get
	...
2011/11/8-30 [Computer/SW/Security, Computer/SW/OS/Windows] UID:54218 Activity:nil
11/8    ObM$Sucks
        http://technet.microsoft.com/en-us/security/bulletin/ms11-083
        \_ How is this different from the hundreds of other M$ security
           vulnerabilities that people have been finding?
           \_ "The vulnerability could allow remote code execution if an
               attacker sends a continuous flow of specially crafted UDP
	...
2011/11/11-30 [Computer/SW/Security] UID:54224 Activity:nil
11/11   MacOSX's Sandbox security hole:
        http://preview.tinyurl.com/7ph2wtg [arstechnica]
	...
2011/2/10-19 [Computer/SW/Security] UID:54034 Activity:nil
2/9     http://www.net-security.org/secworld.php?id=10570
        Summary: iPhone passwd storage is unsafe after all
	...
Cache (389 bytes)
ssh.com
NetSec 2004 SF, USA, June 14-16 The new version of SSH Tectia introduces seamless integration with enterprise identity management and enhanced PKI compatibility reducing the total costs of managed security middleware. FIPS 140-2 Certification The encryption module used in SSH Tectia Client/Server 40 has been awarded Level 1 FIPS 140-2 certification for Windows, UNIX and Linux platforms.