Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×
Security

Flaw Made Public In OpenSSH Encryption 231

alimo20 writes "Researchers at the Royal Holloway, University of London have discovered a flaw in Version 4.7 of OpenSSH on Debian/GNU Linux. According to ISG lead professor Kenny Patterson, an attacker has a 2^{-18} (that is, one in 262,144) chance of success. Patterson tells that this is more significant than past discoveries because 'This is a design flaw in OpenSSH. The other vulnerabilities have been more about coding errors.' The vulnerability is possible by a man-in-the-middle intercepting blocks of encrypted material as it passes. The attacker then re-transmits the data back to the server and counts the number of bytes before the server to throws error messages and disconnects the attacker. Using this information, the attacker can work backwards to figure out the first 4 bytes of data before encryption. 'The attack relies on flaws in the RFC (Request for Comments) internet standards that define SSH, said Patterson. ... Patterson said that he did not believe this flaw had been exploited in the wild, and that to deduce a message of appreciable length could take days.'"
Image

Sedate Your Kids While They Play 264

If your child won't sit still at the dentist, the doctor, or the kitchen table, you need the PediSedate Helmet. The device consisting of a colorful headset that connects to a game component or a portable CD player. After a snorkel attachment goes into the child's mouth, the helmet will monitor respiratory function and distribute nitrous oxide or anesthetic gas. The company website states, "The child comfortably becomes sedated while playing with a Nintendo Game Boy system or listening to music. This dramatically improves the hospital or dental experience for the child, parents and healthcare providers."
Government

US Federal Government Launches Data.gov 109

Elastic Vapor writes "I'm happy to announce that the US Federal Government earlier today launched the new Data.Gov website. The primary goal of Data.Gov is to improve access to Federal data and expand creative use of those data beyond the walls of government by encouraging innovative ideas (e.g., web applications). Data.gov strives to make government more transparent and is committed to creating an unprecedented level of openness in Government. The openness derived from Data.gov will strengthen the Nation's democracy and promote efficiency and effectiveness in Government." I hope the data reported will be impartially selected, honestly gathered, clearly explained, and perfectly accurate. Perhaps they could start with inspiration from the Concord Coalition's National Debt Counter.

Slashdot Top Deals

Never test for an error condition you don't know how to handle. -- Steinbach

Working...