Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror

Slashdot videos: Now with more Slashdot!

  • View

  • Discuss

  • Share

We've improved Slashdot's video section; now you can view our video interviews, product close-ups and site visits with all the usual Slashdot options to comment, share, etc. No more walled garden! It's a work in progress -- we hope you'll check it out (Learn more about the recent updates).

×
Privacy

+ - Lax SSH key management a big problem

Submitted by cstacy
cstacy (534252) writes "Tatu Yionen, inventor of SSH, says he feels "a moral responsibility" to come out of retirement and warn that a "little-noticed problem" could jeopardize the security of much of the world's confidential data. He is referring to the management (or lack thereof) of SSH keys (i.e. "authorized_keys") files. He suggests that most organizations simply allow the SSH key files to be created, copied, accumulated, and abandoned, all over their network, making easy pickings for intruders to gain access.

Do you think this is a widespread problem?
How does your company manage SSH keys?"
This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

Lax SSH key management a big problem

Comments Filter:

% APL is a natural extension of assembler language programming; ...and is best for educational purposes. -- A. Perlis

Working...