theweaselking: (Default)
[personal profile] theweaselking
MOTHERFUCKER.

If you have a Debian or Ubuntu system, update *now* and delete all SSH and SSL certificates and keys you generated before the update. Generate new ones, unless you installed openssh TODAY.

For Ubuntu, this affects 7.04+. 6.06 is safe. For Debian, fucked if I know. Debian is obsolete, pretty much by definition.

(no subject)

Date: 2008-05-14 10:59 pm (UTC)
From: [identity profile] jagash.livejournal.com
Soo glad that I haven't used my ubuntu installation for anything concrete. Lower risk, though I will have to update immediately upon booting into that system. Thanks.

(no subject)

Date: 2008-05-14 11:50 pm (UTC)
From: [identity profile] drjon.livejournal.com
Same here. Many thanks!

(no subject)

Date: 2008-05-14 11:00 pm (UTC)
From: [identity profile] elffin.livejournal.com
ngyagh. Thankee.

(no subject)

Date: 2008-05-14 11:02 pm (UTC)
ext_195307: (Computer)
From: [identity profile] itlandm.livejournal.com
Ubuntu 8's upgrader dealt with it once I gave it the go-ahead. But yeah, a revolting development. Let us hope it doesn't become a habit.

(no subject)

Date: 2008-05-14 11:20 pm (UTC)
From: [identity profile] theweaselking.livejournal.com
You did reinstall openssh, right?

Because, if you didn't, you didn't generate new certificates. Meaning you're left vulnerable to a MITM attack.

(no subject)

Date: 2008-05-15 12:16 am (UTC)
ext_195307: (Computer)
From: [identity profile] itlandm.livejournal.com
The update program did that. It asked me first though.

(no subject)

Date: 2008-05-14 11:27 pm (UTC)
From: [identity profile] jsbowden.livejournal.com
Those of us not running Linux will just point and laugh.

(no subject)

Date: 2008-05-14 11:32 pm (UTC)
From: [identity profile] theweaselking.livejournal.com
Indeed. And one day, when SSH and SATA support come to you, all these problems will be resolved, in advance.

(Unless you're running a BSD clone, in which case I simply have to say, from experience, MACS SUCK ASS GET A REAL COMPUTER YO.)

(no subject)

Date: 2008-05-14 11:36 pm (UTC)
From: [identity profile] jsbowden.livejournal.com
BSD clone? No no, I run an actual BSD, thanks. FreeBSD to be specific. I've had SSH for a dozen years, and SATA support has been around since SATA chipsets started hitting the market.

(no subject)

Date: 2008-05-14 11:46 pm (UTC)
From: [identity profile] theweaselking.livejournal.com
And, on a fresh install, can you do the whole pointy-clicky-thing and make a second monitor work in, like, two seconds? No[1]? That's what I thought. Dirty mac-user!


[1]: Attempts to turn this question upon Linux users are simply a sign of jealousy. Really. Totally. That's what they are. And you're a poopy head.

(no subject)

Date: 2008-05-14 11:52 pm (UTC)
From: [identity profile] jsbowden.livejournal.com
I may or may not be a poopy head, but yeah, Xinerama is not exactly hard to set up.

The easiest machines to do it on are my Irix boxes. I don't even have to point and click, they just auto detect the second monitor and enable it for you.

(no subject)

Date: 2008-05-15 12:06 am (UTC)
From: [identity profile] theweaselking.livejournal.com
You are the enemy of free software! By which, of course, I mean Linux. Because, y'know, that's what free software IS.

So there!

(no subject)

Date: 2008-05-15 12:14 am (UTC)
From: [identity profile] jsbowden.livejournal.com
Yes, yes I am. I even have Suns running Solaris, which also Just Works (TM) with multiple displays.

(no subject)

Date: 2008-05-15 03:48 am (UTC)
From: [identity profile] plantyhamchuk.livejournal.com
But.... but.... macs are pretty!!

(no subject)

Date: 2008-05-14 11:39 pm (UTC)
From: [identity profile] ben-raccoon.livejournal.com
Suddenly, I'm glad I run gentoo..

(no subject)

Date: 2008-05-14 11:45 pm (UTC)
From: [identity profile] mrbankies.livejournal.com
Yeah, that's pretty much a big deal problem. Yeeek.

(no subject)

Date: 2008-05-15 01:08 am (UTC)
From: [identity profile] anivair.livejournal.com
That patched with this morning's updates on all my servers.

(no subject)

Date: 2008-05-15 02:41 am (UTC)
From: [identity profile] eididdy.livejournal.com
Nice. Installed it last night.

(no subject)

Date: 2008-05-15 06:02 am (UTC)
From: [identity profile] athelind.livejournal.com
Wait, what?

I run Ubuntu (8.04), but I'm sufficiently tech-illiterate that I don't know what SH and SSL codes ARE, other than "something to do with encryption". If I don't deliberately use them, do I have to worry about it?

I THINK my system installed the OpenSSH app this morning, but I'm not sure; I get new updates regularly.

(no subject)

Date: 2008-05-15 11:00 am (UTC)
From: [identity profile] theweaselking.livejournal.com
Okay. SSH and SSL are both traffic encryption applications, so nobody can listen in to what your remote computer is sending to a server, and they use "keys". Keys are generated randomly, but the security of the key depends on *how random* the random number generator really is.

For the last two years, Debian and Ubuntu have had a flaw in their random number generator, so that their "random" keys are really nothing of the sort.

If you have "openssl" and "libssl" and "openssh-server" installed, remove them, update your packages, and reinstall them.

Run "ssh-vulnkey" after updating, to find if there are any remaining vulnerable keys

(no subject)

Date: 2008-05-15 04:25 pm (UTC)
jerril: A cartoon head with caucasian skin, brown hair, and glasses. (Default)
From: [personal profile] jerril
So, does this impact users who aren't running their own servers or doing anything more than visiting HTTPS enabled websites?

(no subject)

Date: 2008-05-15 05:03 pm (UTC)
From: [identity profile] theweaselking.livejournal.com
If you aren't using SSH to connect to your machine and you aren't running an SSL service like HTTP or FTP, then why do you have the services installed?

If you have them installed, you must update them. Period. If you don't have them installed, no worries.

(no subject)

Date: 2008-05-15 06:25 am (UTC)
From: [identity profile] atlasimpure.livejournal.com
hahahahahahahaha

Profile

theweaselking: (Default)theweaselking
Page generated Feb. 6th, 2026 05:25 am