Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on lemmy.world

4 replies

Soo, the point is to not enable features that undermine security, like using an FQDN as a key (or source of a key) and to enable features that reduce DoS, like a connection timeout. Does not sound like bugs, just like missing default options.

It's still important to not use the affecting options.

9

Hot take: Might be wise to adopt the security by obscurity model and go with an OS that is hardened (ideally, a formally verified microkernel like sel4) or runs in a custom VM/container with almost zero attack surface area.

6
lemmy.world

The single biggest attack vector for SSH is IPv4. Disable it and 99% of issues go away.

4

You reached the end

OpenSSH vulnerabilities could pose huge threat to businesses everywhere | Spyke