Live data from Hacker News

Black Hat 2024: Secure Shells in Shambles [pdf]

i.blackhat.com

11–20 of 33 posts

Re: Black Hat 2024: Secure Shells in Shambles [pdf]

#11
post #4

SSH and other services can be further protected by Single Packet Authentication (SPA), https://github.com/mrash/fwknop > SPA requires only a single packet which is encrypted, non-replayable, and authenticated via an HMAC in order to communicate desired access to a service that is hidden behind a firewall in a default-drop filtering stance. The main application of SPA is to use a firewall to drop all attempts to conne…

Every now and then I use GnuPG encrypted emails (or a web form) to my servers to open the firewall for certain IP addresses. If the server can decrypt such a message it can safely act on it. The server's default is to only allow certain network ranges to access certain ports, e.g. from my local providers or employers networks.

Doesn’t wireguard solve the same issue? Crypto key packet authentication?

Re: Black Hat 2024: Secure Shells in Shambles [pdf]

#12
post #10
post #2

The Secure Shell (SSH) protocol has survived as an internet-facing management protocol for almost 30 years. Over the decades it has transformed from a single patented codebase to a multitude of implementations available on nearly every operating system and network-connected device. This presentation dives deep into the Secure Shell protocol, its popular implementations, what's changed, what hasn't, and how this leads…

I didn't realise the old ssh.com codebase was patented, apart from crypto patents like RSA (or IDEA?)

See perhaps:

* https://www.ssh.com/legal/patents/

* https://patents.justia.com/assignee/ssh-communications-secur...

Re: Black Hat 2024: Secure Shells in Shambles [pdf]

#14
post #13

a lot to grasp in this one. anyone know if a video is available ?

Usually will be in the weeks or months after. I don’t know what the reasons are for the variance though.

If you use YouTube, subscribing there should get you notified when defcon starts releasing them all.

Re: Black Hat 2024: Secure Shells in Shambles [pdf]

#15

SSH and other services can be further protected by Single Packet Authentication (SPA), https://github.com/mrash/fwknop > SPA requires only a single packet which is encrypted, non-replayable, and authenticated via an HMAC in order to communicate desired access to a service that is hidden behind a firewall in a default-drop filtering stance. The main application of SPA is to use a firewall to drop all attempts to conne…

So instead of exposing thoroughly tested OpenSSH to the web, I’m exposing this thing, which can also run shell commands…

Just had a random thought… what about port knocking, but the combination was TOTP’d? Port knocking is visible to third parties… but if the combination was a TOTP nonce, guessing the correct combination would be fairly difficult.

Re: Black Hat 2024: Secure Shells in Shambles [pdf]

#18
post #4

Earlier quoted context omitted.

Every now and then I use GnuPG encrypted emails (or a web form) to my servers to open the firewall for certain IP addresses. If the server can decrypt such a message it can safely act on it. The server's default is to only allow certain network ranges to access certain ports, e.g. from my local providers or employers networks.

Doesn’t wireguard solve the same issue? Crypto key packet authentication?

Same question. Can someone chime in on how deploying this would be different from putting ssh behind wiregaurd? On first glance it looks like if you were ultra paranoid you could put this in front of wiregaurd and not even have to open up a udp port? Would that be an advantage to add a layer to secure wiregaurd against 0day?

Re: Black Hat 2024: Secure Shells in Shambles [pdf]

#19
post #17

What is the fancy htop-like program displayed on page 44? It reminds me of the DeLorean dashboard in Back To The Future :)

Reading your comment I was putting my money on a customized glances - but after checking the slide... Nope, that's just the default view for btop++ (first screenshot in the link)

https://github.com/aristocratos/btop

Re: Black Hat 2024: Secure Shells in Shambles [pdf]

#20
post #19
post #17

What is the fancy htop-like program displayed on page 44? It reminds me of the DeLorean dashboard in Back To The Future :)

Reading your comment I was putting my money on a customized glances - but after checking the slide... Nope, that's just the default view for btop++ (first screenshot in the link) https://github.com/aristocratos/btop

Wow, thank you so much for showing me this. I'll check out glances, too.

Any other badass TUI dashboards out there?

I wish there were a way to expose these as webpages.

Post reply on HN