Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #186752
| From | Michael Stone <mstone@debian.org> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Buster SSH |
| Date | 2017-09-13 20:20 +0200 |
| Message-ID | <upkqt-2qd-1@gated-at.bofh.it> (permalink) |
| References | (3 earlier) <uoG9I-1yX-13@gated-at.bofh.it> <uoXtU-4mv-1@gated-at.bofh.it> <uoXNf-4I9-19@gated-at.bofh.it> <uphVE-H9-21@gated-at.bofh.it> <upjE7-1RR-37@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Wed, Sep 13, 2017 at 12:27:53PM -0500, Nicholas Geovanis wrote: >Just thinking out loud for those who won't read that article: >One of its main points is not that DSA is cryptographically weak, as has been >broadly mentioned. Rather that a coding flaw in ssh-keygen limits the key-size >for DSA to 1024 because the developers did not track the evolving FIPS >standards. And DSA is extremely sensitive to good random numbers, which are fairly hard to guarantee. And 1024 bit DSA is definitely too small, but larger DSA keys won't work on existing SSH implementations--from a practical standpoint, there aren't openssh servers which will take a larger, secure DSA key but won't take some other kind of key. Since there isn't a compelling reason to use DSA instead of an already-supported algorithm+keylength, why bother rolling out a change to the DSA keys? In general the security community has found that it's better to have a smaller number of well chosen options than a lot of options with little to distinguish them--when faced with too many choices, people tend to pick the wrong one. And as a bonus, elliptic curve keys are a lot smaller and a lot easier to copy & paste than humongous DSA keys. Mike Stone
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-11 21:10 +0200
Re: Buster SSH Cindy-Sue Causey <butterflybytes@gmail.com> - 2017-09-11 23:50 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 00:40 +0200
Re: Buster SSH "Alexander V. Makartsev" <avbetev@gmail.com> - 2017-09-12 01:20 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 01:50 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 19:50 +0200
Re: Buster SSH Greg Wooledge <wooledg@eeg.ccf.org> - 2017-09-12 20:10 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 22:00 +0200
Re: Buster SSH Don Armstrong <don@debian.org> - 2017-09-13 17:40 +0200
Re: Buster SSH Nicholas Geovanis <nickgeovanis@gmail.com> - 2017-09-13 19:30 +0200
Re: Buster SSH Michael Stone <mstone@debian.org> - 2017-09-13 20:20 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-13 19:40 +0200
Re: Buster SSH Sven Hartge <sven@svenhartge.de> - 2017-09-14 00:30 +0200
csiph-web