[Ambassadors] Debian Bug Leaves Private SSL/SSH Keys Guessable

Rahul Sundaram sundaram at fedoraproject.org
Thu May 15 13:15:12 UTC 2008


Elio Tondo wrote:
> Sorry if this is somewhat off-topic, but it's good to know that Fedora 
> is immune from this bug... "This problem not only affects Debian, but 
> also all its derivatives, such as Ubuntu."
> 
> http://it.slashdot.org/article.pl?sid=08/05/13/1533212&from=rss

Well, not quite immune. If you have Fedora boxes that does ssh key 
authentication with Debian boxes, you can still be compromised. There 
are good discussions on how we can avoid similar problems however. Our 
upstream focus is generally a very good thing to mitigate such issues.

Rahul




More information about the Fedora-ambassadors-list mailing list