IETF-SSH archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: When SSH standards noncompliance is a "feature"
Jeffrey T. Hutzelman <jhutz%cmu.edu@localhost> writes:
>About the only thing this does is prevent security scanning software from
>reporting the apparent presence of a vulnerable version.
Yup, and that's exactly the reason for doing it: You don't need to fix a vuln
when the scanner can't tell anyone you have it.
As Raymond Chen likes to say, "I bet somebody got a really nice bonus for that
feature".
Peter.
Home |
Main Index |
Thread Index |
Old Index