Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] bootable linux with sshd
- Date: Wed, 3 Jan 2007 13:56:05 +0900
- From: "Fergal Daly" <fergal@example.com>
- Subject: Re: [tlug] bootable linux with sshd
- References: <875029960701012011u45dca8advd89f700e6a91008@example.com> <370858.33065.qm@example.com> <875029960701012334m211b2711l6e4b178a281dc8a2@example.com> <459A1304.9060301@example.com> <875029960701020307u5c9f75c1n2d720e843d900294@example.com> <875029960701020824m66a81709i1070d220954f888d@example.com> <Pine.NEB.4.64.0701031016200.1055@example.com> <875029960701021954y3a94ceebu3d8f0cbc97c0f3af@example.com> <Pine.NEB.4.64.0701031323590.1055@example.com>
On 03/01/07, Curt Sampson <cjs@example.com> wrote:For this particular case, you've gone right off the rails.
If the attack you're defending against is *only* guessing of the secrets necessary to log in to that computer, you'd be correct. But in that case, given that an ssh private key contains very nearly the same amount of information (i.e., is almost exactly "as long") as an ssh private key plus two long passphrases, there's no point in using anything but the ssh key.
However, this is not the attack you're defending against. Nobody's going to guess that in your lifetime.
So, if they need an ssh key to log in (which they do if you've disabled password logins), they need to steal it. Someone with access to your hardware could probably do this without too much difficulty. Once
Someone with access to my hardware could key-sniff my ssh passphrase and sudo password. There is pretty much no defense against someone with access to my hardware (beyond military hardening and tamper proof seals etc). I have never checked whether a software key sniffer has been installed on any of my machines, I probably never will similarly for a hardware key sniffer.
I am not defending myself against this attack. If you genuinely are defending yourself against this attack then you should really have even more hardware - like a one-time-secret card etc, otherwise you are not really defended,
F
- Follow-Ups:
- Re: [tlug] bootable linux with sshd
- From: Curt Sampson
- References:
- [tlug] bootable linux with sshd
- From: Fergal Daly
- Re: [tlug] bootable linux with sshd
- From: Gerald Naughton
- Re: [tlug] bootable linux with sshd
- From: Fergal Daly
- Re: [tlug] bootable linux with sshd
- From: Al Hoang
- Re: [tlug] bootable linux with sshd
- From: Fergal Daly
- Re: [tlug] bootable linux with sshd
- From: Fergal Daly
- Re: [tlug] bootable linux with sshd
- From: Curt Sampson
- Re: [tlug] bootable linux with sshd
- From: Fergal Daly
- Re: [tlug] bootable linux with sshd
- From: Curt Sampson
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] bootable linux with sshd
- Next by Date: Re: [tlug] bootable linux with sshd
- Previous by thread: Re: [tlug] bootable linux with sshd
- Next by thread: Re: [tlug] bootable linux with sshd
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links