Important SSH patch coming soon
marc.info
marc.info
http://linux.die.net/man/5/ssh_config contains no mention of it, and DDG hits a reddit thread of 2014 asking the same thing (and giving an indication that it was also subject to another vuln) and they stated that it was added undocumented but "it does nothing yet"...
I found a commit message saying "Request roaming to be enabled if UseRoaming is true and the server supports it." So in addition, what is "request roaming"?
This is for people who are on cell connections/spotty internet.
https://launchpad.net/ubuntu/+source/openssh/1:5.9p1-5ubuntu...
*Edit : it does seems like a good idea to disable the feature on your local `ssh_config` in case you or a software you use connect to an unpatched evil server.
The vulnerability is in the OpenSSH client, not the server. ssh_config is the client configuration. Unpatched servers are not relevant and putting this option in your server configuration (sshd_config) will simply make it not start, because the configuration is invalid.
"experimental support for resuming SSH-connections (roaming) ... could be tricked by a malicious server into leaking ... private client user keys."
Come on Theo, this isn't Linux
UseRoaming no
to your ssh_config systemwide or add Host *
UseRoaming no
to your ~/.ssh/config. It's a client bug: no need to change sshd_config.Most of the web sites have a tendency of emptying your data plan, so, I would understand if people are hesitant on opening the web page.
And the person visited the website who gave the summary. Presumably they already knew.