OpenSSH 7.0 released
openssh.com
openssh.com
That seems like a pretty significant "oops" to have gone unnoticed for two releases?
I remember exploiting this issue more than a decade ago: http://seclists.org/bugtraq/1999/Sep/432
[1] http://www.azarask.in/blog/post/a-new-type-of-phishing-attac...
There was (and might still be) an escape sequence that allowed setting the xterm title, and another sequence that caused that title to be sent to the terminal AS INPUT!
I'd imagine this latter control sequence was eliminated.
I guess I upgraded to an RSA key "just in time", though obviously far later than I apparently should have.
I still use arcfour; it seems to be the fastest when using scp or rsync (rsync -e 'ssh -c arcfour') for copying large files. I hope the OpenSSH package manager for my distribution keeps arcfour enabled for this reason.
OpenSSH since the 6.5 release (http://www.openssh.com/txt/release-6.5) has a better alternative, ChaCha20. It's even faster than RC4, and has no known weaknesses AFAIK. Some more information: https://security.stackexchange.com/questions/46812/what-does...
$ for c in $(ssh -Q cipher); do echo $c; dd if=/dev/zero bs=1M count=8K | ssh -o Compression=no -c $c localhost dd of=/dev/null 2>/dev/null; done* Support for ssh-dss, ssh-dss-cert-* host and user keys is disabled by default at run-time. These may be re-enabled using the instructions at http://www.openssh.com/legacy.html
* sshd(8): fix circumvention of MaxAuthTries using keyboard-
interactive authentication. By specifying a long, repeating
keyboard-interactive "devices" string, an attacker could request
the same authentication method be tried thousands of times in
a single pass. The LoginGraceTime timeout in sshd(8) and any
authentication failure delays implemented by the authentication
mechanism itself were still applied. Found by Kingcope.
That's a pretty big hole. See also: http://seclists.org/fulldisclosure/2015/Jul/92Summary
+ New default: PermitRootLogin prohibit-password, which also prohibits all interactive login forms.
+ DSS keys are finally disabled by default
+ Use at least 2048 bits for your RSA keys
+ Deprecating or disabling MD5, SHA1, Blowfish CBC, ARC4, and a few other older ciphers/hmac's.
+ Bug and vuln fixes
It says they only plan on "refusing all RSA keys smaller than 1024 bits" (e.g. 768 bits.
> Deprecating or disabling SHA1
SSH1, not SHA1!
yeah, I added that .. 2048 is really minimum best practice these days ;)
SSH1, not SHA1!
Good point, edited - btw next paragraph also says disabling 1024 bit diffie-hellman-group1-sha1 key exchange.
Which turns out to be a Cloud solution that promises "root privileges with just one mouse click" across all my servers. What could possibly go wrong?
I could probably easily write it - just haven't had a chance to do it.
I'm experienced enough to the point where if I was going to do something stupid - typing in sudo won't stop me from doing it (I'm not saying I'm an expert - I'm saying that sudo has become muscle memory so it doesn't register in my mind).
The added benefit to the message is a notification in the event that the system is compromised.
It's an unfortunate fact of life that most large enterprises require the ability to quickly grant and revoke permissions across the enterprise. Some enterprises literally have no formal user deprovisioning process (even manual) across Linux/UNIX servers. Given that the only real alternative out there right now is LDAP, we think Userify is a pretty cool fix.
However, any powerful authorization framework can be dangerous, and the more power, the more danger. It's definitely a fair point.
We designed this as safely as we could: Userify doesn't need (or want) secret credentials, only public keys. We encrypt with NaCl before data hits Redis. We only communicate with TLS. The Userify shim does need root permissions because it's managing user accounts.
Userify is available for on-premise deployment (currently Enterprise, and, soon, Pro in your AWS VPC), and Cloud is available for people who want free. Soon, we're launching "Pro", which is an in-between product for people who want in-VPC without paying enterprise pricing.
(I assume you're talking about RH IPA, which is some nifty wrappers around LDAP. As someone who spent a lot of time implementing LDAP on UNIX at big companies, LDAP and centralized auth in general carries a lot of risks: for example, what happens if just a single one of your boxes is compromised, and rather than just sniff passwords, it starts DoS'ing your LDAP server? oops. now you can't get into any of your servers, even the ones they haven't yet owned.)
We focus on a lot more than just authentication. That's just the beginning of the story.
Userify Enterprise provides layered role-based access control, a user-friendly front-end for key updates, project functionality, and the ability to remove users across a single project or the entire companies. Ansible or Puppet don't offer any of those things. We have built-in deployment for Chef, for instance. We try hard not to duplicate functionality that you can get elsewhere (for example, systems management, log monitoring.)
Those are designed for systems management, and they're good at that. We're designed for complex, multi-tiered user management with a focus on the user, not the system. (Hence our name) We view these as orthogonal directions, and it makes sense to use Userify with a good devops/cf system like Ansible/Chef/Puppet/Salt/etc.
Small shops can still manually manage a dozen or so users across a few groups of servers. We've got a bunch of companies with hundreds of servers and less than 10 devops across all of them.
For companies like that, Userify gives a bunch of other benefits.. for example, you can rotate your SSH keys without requesting a production code deployment, or update an SSH key without write access to git, or remove a contractor's account on their last day, etc.
On-boarding and off-boarding get a lot easier, rotating keys is easier, training users is easier, managing lots of different role sets is easier, and Userify doesn't require any changes to PAM or NSS modules -- installing is a one-liner and it just uses /usr/sbin/adduser and /etc/sudoers.d.
The shim is just a few hundred lines.. read through it at https://github.com/userify/shim
OpenSSH + Userify = authtopia.
Disclaimer: I am founder of Userify.
FTFY.