=== weechat1 is now known as Oblivion [16:57] TJ-: um, question: has that been escalated to OpenSSH yet? [16:57] (the shielded pke problem) [16:58] (private key extraction*) [17:17] not by me [17:18] I assumed due to the blog post and talk on HN that it'd be all over the place === riderjj is now known as juanjo [17:57] check [17:57] if a CVE was assigned for this it hasn't been reported on oss-security yet. Or it's been embargoed... [18:05] can you assign a CVE to security theatre? [18:05] good point. BUT i'm surprised this didn't hit oss-security heh [18:06] whatever the process does to encrypt the key in memory can be trivially reversed if you can dump the process memory space like the script does [18:06] you can make it harder, but that only makes the script slightly more complicated [18:08] the question is...if that was put in place to prevent sidechannel attacks, is it still good enough to prevent some sidechannel attacks?