IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: When SSH standards noncompliance is a "feature"



Jeffrey T. Hutzelman <jhutz%cmu.edu@localhost> writes:

>About the only thing this does is prevent security scanning software from
>reporting the apparent presence of a vulnerable version.

Yup, and that's exactly the reason for doing it: You don't need to fix a vuln
when the scanner can't tell anyone you have it.

As Raymond Chen likes to say, "I bet somebody got a really nice bonus for that
feature".

Peter.




Home | Main Index | Thread Index | Old Index