[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: SSH with potato, not very secure?



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

>>>>> "Richard" == Richard  <ricv@denhaag.org> writes:

Richard> Use Openssh, opensource leeds to more secure systems and I
Richard> belive it has less security bug's. (just keep updated)

Not true.  Open source has the *potential* to be more secure (due to
peer review, etc.), but it does not necessarily lead to more security.
In the case of commercial ssh vs. OpenSSH, you can get access to
commercial ssh's source, and so if you don't trust it, you can always
audit it yourself.  And being a critical security tool, I'm sure many
others have already done some auditing of the code.  So in this case,
open source doesn't really give you much more in terms of security.

On the other hand, OpenSSH was created by the OpenBSD people, who are
famous for secure programming.

- -- 
____     |     -----------------------------------------------------------
|  /   --+--
| /   ___|___    Hubert Chan <hackerhue@crosswinds.net>
| \   | _|_ |
|__|  |__|__|    PGP/GnuPG fingerprint: 6CC5 822D 2E55 494C 81DD
|        |                              6F2C 6518 54DF 71FD A37F
|      / | \     Key at http://www.crosswinds.net/~hackerhue/hackerhue.asc
|     /  |  \
|        |     <><------------------ http://www.crosswinds.net/~hackerhue/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.4 (GNU/Linux)
Comment: Processed by Mailcrypt 3.5.5 and Gnu Privacy Guard <http://www.gnupg.org/>

iD8DBQE6noc1ZRhU33H9o38RAmycAKCD3uyV4Qr/ANKrD3vF+8sanasCWgCfdOaK
9Nyn3/K99A26AgNFiQTgJPg=
=nXSY
-----END PGP SIGNATURE-----



Reply to: