Well, the cat is out of the bag, and apparently this terrible remote exploit which affected OpenSSH and required that Theo demand that the entire planet upgrade to OpenSSH 3.3 immediately, even though he himself admitted that the new version doesn't actually fix the bug, but makes it somehow immune to the exploit, is now fully revealed to us. Apparently the entire world is running BSD and/or S/Key authentication. Who wants to start a pool to guess how long before Debian has another package release just to disable protocol separation? :) (This new version is creating about five new bug ids for them) Theo De Radt Makes An Ass Of Himself |