Contributed by Dengue on from the drop-your-privileges-and-reach-for-the-sky-fishy dept.
"Niels Provos posted the following on Tech@OpenBSD.org" :I've been told integration into OpenBSD is planned. Here's a snippet from privsep.html :Hi, Markus and I have been working on a completely privilege separated OpenSSH so that problems similar to the channel bug or the zlib double free would not affect us in the future. The code is in a very good shape right now. If you would like to get more information or try a current snapshot, see http://www.citi.umich.edu/u/provos/ssh/privsep.html Greetings, Niels.
"Previously any corruption in the sshd could lead to an immediate remote root compromise if it happened before authentication, and to local root compromise if it happend after authentication. Privilege Separation will make such compromise very difficult if not impossible."
(Comments are closed)
By Andy () on
By jesse s. () on
-jesse