Also, scary that SSH appears to be partially affected(?)
Also, scary that SSH appears to be partially affected(?)
Because all the countries still can't get along with each other, and thus export restrictions still exist.
http://en.wikipedia.org/wiki/Export_of_cryptography_from_the...
Well, yeah, that's the idea—"export-grade cryptography" essentially means means "cryptography we, as a state actor, can win against in a cyberwar."
"cryptography we, as a state actor, can win against in a cyberwar, but which ultimately will end up being exploited at home as well, since we're all using the same partially broken code base"
Yeah. Is it sufficient to set ServerKeyBits to 2048?
Be careful: not all clients support the newest algorithms. Example: Ubuntu 12.04 ssh client doesn't support curve25519-sha256@libssh.org (I'm still googling how to upgrade to the latest openssh, anybody has the answer?)
In general, check that you are still able to connect to your server before closing your last ssh connection to it.
What they are refering to is the Key Exchange method named "diffie-hellman-group1-sha1" which uses a 1024-bit DH group. You can disable this with use of the KexAlgorithms parameter. Starting with OpenSSH 6.6 it is already disabled on the server side, but still allowed with the client. There are severe interoperability problems with embedded devices if disabled.