The cipher 'none' in OpenSSH

Phil Karn karn at ka9q.ampr.org
Sat Jan 15 07:25:31 EST 2000


It's been suggested to me that I use blowfish if I am more concerned
with speed than with security.

Wasn't there some weakness in the SSH protocol if the null cipher were
supported in the endpoints even if the user doesn't choose it? It may
have been a vulnerability to a man-in-the-middle attack, I'm not sure.

Phil






More information about the openssh-unix-dev mailing list