This is a tag from the blog of Rod Begbie, who is one…
                       XXXX

“Groovy Motherfucker”

Filed under 'debian'

May 15, 2008

Debian OpenSSL Predictable PRNG Toys

More details on the Debian openssl patch farrago. Important point: Every sysadmin needs to scan their boxes (not just Debian users) to find any compromisable .authorized_keys

May 14, 2008

The Debian SSL fubar farrago - some light perspective

If you have a Debian or Ubuntu box and used it to generate an SSH key in the last couple of years, due to a rather heinous bug, there’s a high chance you have one of roughly 260,000 keys.

To put this in perspective, if your account was protected by a 4 lower-case-character password, it would be harder to brute-force access (264 = 456,976).

For the sake of the internet, follow the instructions to update the keys on your servers forthwith.

saute-swinish