"In a first, cryptographic keys protecting SSH connections stolen in new attack"

https://arstechnica.com/security/2023/11/hackers-can-steal-ssh-cryptographic-keys-in-new-cutting-edge-attack/

I read most of this article trying to determine if I was impacted, so to save you the trouble:

The researchers traced the keys they compromised to devices that used custom, closed-source SSH implementations that didn’t implement the countermeasures found in OpenSSH and other widely used open source code libraries.

52 points · 3 comments · view on lemmy.world

3 Comments

ghostface@lemmy.world · 10 pts · 2y

You da real mvp

pudcollar@lemmy.ml · 7 pts · 2y

tldr 1 in a million RSA keys are vulnerable

BestBouclettes@jlai.lu · 1 pts · 2y

I migrated most of my keys to ed25519 a while ago, I probably should keep going