Techrights logo

IRC: #techbytes @ FreeNode: Friday, May 08, 2020

Join us now at the IRC channel.

*Condor has quit (Ping timeout: 256 seconds)May 08 04:10
schestowitz>> Subject: Fwd: Possible CollaborationMay 08 05:29
schestowitz>> Another time waster or is it worth it?May 08 05:29
schestowitz> Too little info to say.  A plaintext or non-PDF CV would be interesting.May 08 05:29
schestowitz> Hi Dr Roy,May 08 05:31
schestowitz>May 08 05:31
schestowitz> I saw your profile through your Twitter account, I've been learningMay 08 05:31
schestowitz> Software Development on my own, and I noticed you offer SoftwareMay 08 05:31
schestowitz> Development services. I was wondering if I could join your team as anMay 08 05:31
schestowitz> Intern. I'm willing to provide more information about myself.May 08 05:31
schestowitzHi,May 08 05:31
schestowitzWe recently had someone volunteering herself for an internship. After we invested hours teaching her things and preparing she produced nothing at all, so we want some sort of commitment from an intern, assuring it will result in practical things. Do you want to do writing or coding? Have you done internships before?May 08 05:31
schestowitz> Adding to the backlog, TM is using a very weak, deprecated ssh-rsaMay 08 05:41
schestowitz> public key algorithm for host authentication:May 08 05:41
schestowitz>May 08 05:41
schestowitz> $ ssh -o HostKeyAlgorithms=-xxxxxxxMay 08 05:41
schestowitz> Unable to negotiate with xxxport 22: no matching host key typeMay 08 05:41
schestowitz> found. Their offer: ssh-rsa,ssh-dssMay 08 05:41
schestowitz>May 08 05:41
schestowitz> TR is ok, as far as I can tell.May 08 05:41
schestowitzIs this applicable only to passwordless logins?May 08 05:41
schestowitzRe: TM and old host keysMay 08 05:41
schestowitz>> Is this applicable only to passwordless logins?May 08 06:19
schestowitz> Those would be user keys not host keys.May 08 06:19
schestowitzSecurity wise, with that VM that's not firewalled, I don't even think that's the greatest of threats. Surely we need a plan of upgrades. We need to think aboutMay 08 06:19
schestowitz-Drupal upgrade (or shift to another CMS, which might not scale well because there are many nodes)May 08 06:19
schestowitz-OS upgradeMay 08 06:19
schestowitz-move away from VMs, e.g. to containersMay 08 06:19
schestowitzThe upside is, the VMs now seem more stable. I reckon the software update to qemu et al achieved this. But we still need sudoers fixed. I keep pushing for that happen... I suppose until something is very urgent (like HV/VM down) that won't happen...May 08 06:19
schestowitz> Host keys are the keys that TM uses to authenticate itself to any of usMay 08 06:19
schestowitz> as we try to log in and are where this problem manifests.  So, thisMay 08 06:19
schestowitz> shortcoming is related to all logins connecting to TM, whether usingMay 08 06:19
schestowitz> password authentication or key-authentication.  It makes it relativelyMay 08 06:19
schestowitz> easy, computationally, to imitate TM for a MitM when authenticating withMay 08 06:19
schestowitz> passwords:May 08 06:19
schestowitz>May 08 06:19
schestowitz> "If the host key verification fails and no otherMay 08 06:19
schestowitz> supported host key types are available, the serverMay 08 06:19
schestowitz> software on that host should be upgraded."May 08 06:19
schestowitz>May 08 06:19
schestowitz> https://www.openssh.com/txt/release-8.2May 08 06:19
schestowitz>May 08 06:19
schestowitz> and linked to from there:May 08 06:19
schestowitz>May 08 06:19
schestowitz> "Therefore, the same attacks that have been practicalMay 08 06:19
schestowitz> on MD5 since 2009 are now practical on SHA-1. InMay 08 06:19
schestowitz> particular, chosen-prefix collisions can break signatureMay 08 06:19
schestowitz> schemes and handshake security in secure channelMay 08 06:19
schestowitz> protocols (TLS, SSH). We strongly advise to remove SHA-1May 08 06:19
schestowitz> from those type of applications as soon as possible."May 08 06:19
schestowitz>May 08 06:19
schestowitz> https://eprint.iacr.org/2020/014.pdfMay 08 06:19
schestowitzSensitivity of data on that server is limited to user accounts with /hashed/ passwords. AFAIK, there's no direct route from it to TR, only the other way around.May 08 06:19
schestowitz> CentOS has one update [1] available which predates [2] the above warningMay 08 06:19
schestowitz> by a year.  There appear to have been no further updates for thatMay 08 06:19
schestowitz> package on CentOS, even in regards to sha-1 versus rsa-sha2-256/512.May 08 06:19
schestowitz>May 08 06:19
schestowitz> [1] $ yum info openssh-serverMay 08 06:19
schestowitz> Loaded plugins: fastestmirror, securityMay 08 06:19
schestowitz> Repository 'addons' is missing name in configuration, using idMay 08 06:20
schestowitz> Loading mirror speeds from cached hostfileMay 08 06:20
schestowitz>  * base: mirrors.ocf.berkeley.eduMay 08 06:20
schestowitz>  * extras: mirror.chpc.utah.eduMay 08 06:20
schestowitz>  * updates: mirror.lax.genesisadaptive.comMay 08 06:20
schestowitz> Installed PackagesMay 08 06:20
schestowitz> Name        : openssh-serverMay 08 06:20
schestowitz> Arch        : x86_64May 08 06:20
schestowitz> Version     : 5.3p1May 08 06:20
schestowitz> Release     : 118.1.el6_8May 08 06:20
schestowitz> Size        : 702 kMay 08 06:20
schestowitz> Repo        : installedMay 08 06:20
schestowitz> From repo   : updates-copilotcoMay 08 06:20
schestowitz> Summary     : An open source SSH server daemonMay 08 06:20
schestowitz> URL         : http://www.openssh.com/portable.htmlMay 08 06:20
schestowitz> License     : BSDMay 08 06:20
schestowitz> Description : OpenSSH is a free version of SSH (Secure SHell), a program forMay 08 06:20
schestowitz>             : logging into and executing commands on a remote machine. ThisMay 08 06:20
schestowitz>             : package contains the secure shell daemon (sshd). The sshdMay 08 06:20
schestowitz> daemonMay 08 06:20
schestowitz>             : allows SSH clients to securely connect to your SSH server.May 08 06:20
schestowitz>May 08 06:20
schestowitz> Available PackagesMay 08 06:20
schestowitz> Name        : openssh-serverMay 08 06:20
schestowitz> Arch        : x86_64May 08 06:20
schestowitz> Version     : 5.3p1May 08 06:20
schestowitz> Release     : 124.el6_10May 08 06:20
schestowitz> Size        : 330 kMay 08 06:20
schestowitz> Repo        : updatesMay 08 06:20
schestowitz> Summary     : An open source SSH server daemonMay 08 06:20
schestowitz> URL         : http://www.openssh.com/portable.htmlMay 08 06:20
schestowitz> License     : BSDMay 08 06:20
schestowitz> Description : OpenSSH is a free version of SSH (Secure SHell), a program forMay 08 06:20
schestowitz>             : logging into and executing commands on a remote machine. ThisMay 08 06:20
schestowitz>             : package contains the secure shell daemon (sshd). The sshdMay 08 06:20
schestowitz> daemonMay 08 06:20
schestowitz>             : allows SSH clients to securely connect to your SSH server.May 08 06:20
schestowitz>May 08 06:20
schestowitz>May 08 06:20
*TechBytesBot (~b0t@199.19.78.19) has joined #techbytesMay 08 06:20
TechBytesBotHello World! I'm TechBytesBot running phIRCe v0.75May 08 06:20
schestowitz> [2]May 08 06:20
schestowitz> https://centos.pkgs.org/6/centos-updates-x86_64/openssh-server-5.3p1-124.el6_10.x86_64.rpm.htmlMay 08 06:21
-TechBytesBot/#techbytes-centos.pkgs.org | openssh-server-5.3p1-124.el6_10.x86_64.rpm CentOS 6 DownloadMay 08 06:21
schestowitzTBH, we probably ought to leave centos behind and the sooner, the better, depending on when kaniini finds time because he wants to use containers in alpine. One for each CMS, e.g. wiki, wordpress...May 08 06:21
*Condor (~freenode@e1.nixmagic.com) has joined #techbytesMay 08 06:50
*rianne_ has quit (Ping timeout: 256 seconds)May 08 13:18
*rianne_ (~rianne@host81-154-174-226.range81-154.btcentralplus.com) has joined #techbytesMay 08 13:18
*liberty_box has quit (Ping timeout: 264 seconds)May 08 20:01
*rianne has quit (Ping timeout: 264 seconds)May 08 20:01
*liberty_box (~liberty@host81-154-174-226.range81-154.btcentralplus.com) has joined #techbytesMay 08 20:13
*rianne (~rianne@host81-154-174-226.range81-154.btcentralplus.com) has joined #techbytesMay 08 20:13

Generated by irclog2html.py 2.6 by Marius Gedminas - find it at mg.pov.lt!