When is a debian user not a debian user?

| No Comments | No TrackBacks

So lots of people have commented on the potentially very nasty crypto bug in OpenSSL on debian Linux (and derivatives, including Ubuntu) with the good advice of patching and regenerating your SSH keys...

Only thing is, what if you don't have access to the shell to do exactly that....? What if you don't even know you run debian Linux...?

Over the last several years there has been a proliferation of computing "appliances" which almost inevitably run a cut-down Linux underneath the main software stack and in many cases, that's going to be debian Linux.

The thing is, in some cases the vendor won't even explicitly mention what the underlying software is, so the end customer may be blissfully unaware that they have vulnerable machines...

No TrackBacks

TrackBack URL: http://www.mccune.org.uk/blog/rm-mt-tb.cgi/300

Leave a comment

Pages

Powered by Movable Type 4.32-en

About this Entry

This page contains a single entry by Rory2 published on May 15, 2008 10:08 PM.

Are we Secure yet? (Part 1) was the previous entry in this blog.

Avoiding controls which are "designed to fail" is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.