Post #1321970
2024-04-15 19:20 UTC
Replies (9)
-
@cloud_manul@nrw.social 2024-04-15 20:04
@simontatham Hi and thanks for the quick bugfix. From what I know, ecdsa-sha2-nistp521 has never been the default key type in Puttygen, so "normal" keys (mostly ssh-rsa and ssh-ed25519) should be fine?
-
@Filene@dragon.style 2024-04-15 21:07
@simontatham Thank you for your continued development of this application, it's essential and I've relied upon it. πββοΈππ
-
@jcuff@mastodon.mit.edu 2024-04-15 22:15
@simontatham superb write up and repair. Yβall were making safe βkβ before making safe βkβ was cool. Iβm just glad we have folks still around to know how computers work. Thanks team!!
-
@virtuous_sloth@cosocial.ca 2024-04-15 22:22
@simontatham Used such a key with PuTTY, or created such a key with PuTTY?
-
@lispi314@udongein.xyz 2024-04-16 02:40
@simontatham @indigoparadox If I understand from skimming the link, this solely affects PuTTY (on Windows) and /not/ other implementations of SSH, right?
-
@kramse@social.kramse.org 2024-04-16 04:35
@simontatham so sad to hear this news, but assured by the open information! Thanks for your long lasting and hard work on Putty and other projects.
-
@brnrd@bsd.network 2024-04-16 10:49
@simontatham Given that that's 3 additional clicks in the PuTTYgen UI (ECDSA, Dropdown, nistp521) I can almost assure we won't have any in our enterprise. Surprised to see that the default in PuTTYgen 0.81 is still RSA, and only 2048 bits. Ed25519 even works with RHEL 7 (EoL 2024-06-30).
-
@lnr@tech.lgbt 2024-04-16 11:44
@simontatham Also thanks for posting these here. It really helps spread the word!
-
@anonymous236@hachyderm.io 2024-06-11 07:00
@simontatham is ArcosPutty 75.1.8 vulnerable to CVE-2024-31497?