Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Michał "rysiek" Woźniak · 🇺🇦
@rysiek@mstdn.social  ·  activity timestamp last month

so… has mosh been audited yet?

how do we feel about it, security-wise?

#InfoSec #SysAdmin #Linux

  • Copy link
  • Flag this post
  • Block
trystimuli
@tryst@fedi.imu.li replied  ·  activity timestamp last month
@rysiek i’m not much of an auditor, but…

well, the first thing it does upon receiving a packet is extract any ECN, which is a bit weird to do before deciding it’s a valid packet, but it doesn’t use that until after verifying and decrypting the authenticated (AES-OCB3) ciphertext.

it appears to use the same key in both directions because there is an explicit test that the packet is marked for the right direction. i don’t like it, but it doesn’t look to be an actual problem.

i think i’m seeing a single packet per keystroke, and i’m not seeing a random delay in the code. i find this concerning from a extracting keystrokes from timing perspective. but people are still arguing about whether that’s a real concern for ssh…

(this is not getting into the whole terminal emulator aspect)

which brings me to, i think i trust it a bit less than i did an hour ago? but i’m not dropping it immediately now that i looked at it.

  • Copy link
  • Flag this comment
  • Block
mathew
@mathew@universeodon.com replied  ·  activity timestamp last month
@rysiek A security-minded comparison with Eternal Terminal would be good too.
  • Copy link
  • Flag this comment
  • Block
Methylzero
@Methylzero@mast.hpc.social replied  ·  activity timestamp last month
@rysiek
A "wall of death" type mosh pit formed by a large audience on a heavy metal festival. There are hundreds of people involved.
A "wall of death" type mosh pit formed by a large audience on a heavy metal festival. There are hundreds of people involved.
A "wall of death" type mosh pit formed by a large audience on a heavy metal festival. There are hundreds of people involved.
  • Copy link
  • Flag this comment
  • Block
Michał "rysiek" Woźniak · 🇺🇦
@rysiek@mstdn.social replied  ·  activity timestamp last month
@Methylzero oh man wall of death mosh pits are the shit.
  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.2.21 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login