Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 13 Sep 2021 00:44:38 +0200
From:      Tomasz CEDRO <tomek@cedro.info>
To:        Ed Maste <emaste@freebsd.org>
Cc:        freebsd-security <freebsd-security@freebsd.org>, Gordon Tetlow <gordon@tetlows.org>,  Karl Denninger <karl@denninger.net>, Dan Lukes <dan@obluda.cz>
Subject:   Re: Important note for future FreeBSD base system OpenSSH update
Message-ID:  <CAM8r67DdZJphWGvmoHjZmkcF2ormUWus3VZTF-dQJkZ=2KRN2g@mail.gmail.com>
In-Reply-To: <0c3a5f3c-fb07-fae3-22f3-28703c842deb@obluda.cz>
References:  <CAPyFy2A390kS_C3g=Y9QhQcJ06z_FKUxXsNvi9g2CdWF24pukg@mail.gmail.com> <CAPyFy2B04b0GtWoHFQwxht5vK4_cnApPXpDLXU%2BRvcR=2L9YxA@mail.gmail.com> <CAPyFy2Aw8Z3ngiM8YHApjjPRLZVC5MCN8TRQkh6pj2fSeM1zqw@mail.gmail.com> <8169A4A8-B8D1-4265-87C8-74ED4D34FBC8@fasel.at> <2bb56783-2727-9bea-7810-58969d91c00f@denninger.net> <A8BD4882-6DCD-4A5B-BFEF-139C778FE82C@tetlows.org> <0c3a5f3c-fb07-fae3-22f3-28703c842deb@obluda.cz>

next in thread | previous in thread | raw e-mail | index | archive | help
On Mon, Sep 13, 2021 at 12:11 AM Dan Lukes wrote:
> On 12.9.2021 23:27, Gordon Tetlow via freebsd-security wrote:
> > Blaming the browser and other client providers (OpenSSH, etc) for a
> > problem that is 100% because the devices are now abandoned by the
> > manufacturer is the wrong place to focus your anger. We have an
> > enormous problem in the industry of crappy embedded devices (like the
> > OOB management plane) accruing technical security debt while the
> > manufacturers give "a middle finger back" as you say. The
> > supportability of the hardware needs to be baked into the purchasing
> > decision. Commitments from the manufacturers on supportability
> > timeframes are important to understand and budget into a hardware
> > refresh cycle.
>
> "One size fits all" may be acceptable approach for unskilled home users,
> but not for professional use. The security mechanism may be secure
> enough for particular use even if there are known issues with the method
> in question.
>
> There may be a various reason to abandon particular method/algorithm but
> don't claim it's for my security because it's just not true. If
> particular algorithm is not secure enough for me I'm not using it
> despite it's supported. If algorithm is the best for particular case
> (it's why I'm using it) the removal will decrease overall security of
> such system.  In no case the security will be increased.
>
> We should avoid to make decisions on behalf of skilled security officer
> familiar with particular use case.

Hey Ed, It seem that some people are tied to old infrastructure.
Fallback to Port (or custom Kernel / Base?) seems reasonable. Will
there be any alternative solution after upgrade or people will be
forced to leave FreeBSD? Things start to look dramatic :-)

What is the best and worst case scenario of the change?

Is it only Base or also Kernel change?

Would it be possible to use custom build of OpenSSH server (i.e. from
Ports) with old algorithm enabled so it could work in place of the one
being upgraded in base? I can see this approach seems to work for
various services and utilities.

Port seems easiest way to provide alternative solution?

That way we would have secure solution by default and less secure
custom solution but still easy to maintain when there is no other
choice?

-- 
CeDeROM, SQ7MHZ, http://www.tomek.cedro.info



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAM8r67DdZJphWGvmoHjZmkcF2ormUWus3VZTF-dQJkZ=2KRN2g>