/srv/irclogs.ubuntu.com/2021/07/26/#ubuntu-security.txt

=== weechat1 is now known as Oblivion
tewardTJ-: um, question: has that been escalated to OpenSSH yet?16:57
teward(the shielded pke problem)16:57
teward(private key extraction*)16:58
TJ-not by me17:17
TJ-I assumed due to the blog post and talk on HN that it'd be all over the place17:18
=== riderjj is now known as juanjo
tewardcheck17:57
tewardif a CVE was assigned for this it hasn't been reported on oss-security yet.  Or it's been embargoed...17:57
mdeslaurcan you assign a CVE to security theatre?18:05
tewardgood point.  BUT i'm surprised this didn't hit oss-security heh18:05
mdeslaurwhatever the process does to encrypt the key in memory can be trivially reversed if you can dump the process memory space like the script does18:06
mdeslauryou can make it harder, but that only makes the script slightly more complicated18:06
mdeslaurthe question is...if that was put in place to prevent sidechannel attacks, is it still good enough to prevent some sidechannel attacks?18:08

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!