Post #1544720
2024-04-16 06:10 UTC
@lispi314 @indigoparadox PuTTY on any platform, actually. PuTTY can run on Unix too, though it's less popular there. And its ECDSA signing code is the same wherever it's running.
Independent implementations such as OpenSSH aren't affected, that's correct.
Replies (1)
-
@agitatra@berlin.social 2024-04-16 08:03
@simontatham @lispi314 @indigoparadox Am I paranoid when I connect this vulnerability with the xz-backdoor? To get the private keys an attacker needs access to ssh-servers, which the xz-backdoor could have provided. So it's imaginable that the group behind the backdoor found the ecdsa-sha2-nistp521 problem and thought: "how make the most of it"?