Targeted MitM attacks using information leakage in SSH clients [pdf]
fzi.de
fzi.de
We've changed the URL from https://nvd.nist.gov/vuln/detail/CVE-2020-14002 to what seems to be the original source, via https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-2..., which the former article links to.
The comments in this thread are all about PuTTY, which no doubt is because that's all the other article mentioned.
[1]: https://git-scm.com/
Of course, if you don't like the rendering/look/customization of the default PowerShell window, you can also grab Windows Terminal: https://www.microsoft.com/en-us/p/windows-terminal/9n0dx20hk...
I don't want to run a whole VM so I can ssh to a real machine. I don't trust Microsoft with providing a decent terminal experience, were I to run their ssh in their terminal. Frankly, at this point, anything new from Microsoft that does something I can already do is suspect; their new work doesn't feel polished and I'm tired of trying their broken stuff.
Also I haven't seemed to be able to get ssh-agent working there. Maybe just need to look into it more.
But I find PuTTY's terminals to be almost worse. The visuals are seriously eye cancer inducing, and PuTTY's tools don't seem to be built with a terminal-based workflow in mind.
So, I much rather use either MS' OpenSSH port (on Win10) or MSYS 2's (which is included in the Git Bash for Windows, too).
Another approach is to enable "Use Ctrl+Shift+C/V as Copy/Paste" in terminal properties and just use those shortcuts, they seem to work fine in ssh.
Sorry, not buying into the Extend phase. Thank god for Putty and win7 combination still working.
I believe they will get there with Windows terminal (https://github.com/Microsoft/Terminal), I just don’t think they are there yet.
They didn’t launch it with a big splash or anything, but it has saved my butt before.
Host *
(options)In WSL2 isn't that a full-blown VM with another kernel and all? To run an SSH client? shakes head in disbelief
I have moved to macOS since wsl2 came out.
OpenSSH seems affected, too, but have decided to not fix this. As far as I understand the paper, any fix may have undesirable side effects.
The linked paper here https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-2... goes into detail. The PDF is in English, despite the German URL.
That is exactly the reported issue here. PuTTY 0.68 through 0.73 allows the remote attacker to accurately determine whether or not the client has cached the host key. It looks like this works because PuTTY sends a different algorithm list depending on whether or not the key has been cached.
If the MiTM attacker sees the 'default algorithm list' it can be assumed that this is the first connection attempt and the attacker can substitute the server key with a compromised key.
EC2 docs now include that detail, although its labeled as optional.
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/connecti...
On the other hand, I think it's absolutely ridiculous to base one's security around URL recognition, considering all the possible attacks against domain names and URLs.
Cryptographic signatures in a web of trust would be a big step forward here, but unfortunately relatively few people participate.
that that to everyone who downloaded from putty.org
There are certain categories of security-critical software where I feel like it's only increasing surface area for bugs. The idea that PuTTY has bugs that aren't originating from the openssh project is really bothersome to me. All that work to reimplement, for what?
That aside, the official SSH implementation has never been any princess either. The PuTTY implementation is superior in many ways, not least in terms of modularity, although evidently just as prone to security problems as OpenSSH.
I'm all for new alternative implementations of important pieces of our stack, but please God no more security-critical C.
Agreed. OpenSSH wasted a lot of needless effort reimplementing PuTTY. Except now that you know the timeline is reversed I expect your opinion on reimplementation to suddenly 180 as well.
> PuTTY Initial Release: January 8, 1999
> OpenSSH Initial Release: 1 December 1999
Via Wikipedia