Terrapin attacks can downgrade security of OpenSSH connections
When specific popular encryption options are utilized, a new attack known as Terrapin can breach the integrity of the SSH channel by manipulating sequence numbers during the handshake phase, according to academic researchers.
This manipulation enables adversaries to alter or remove messages sent across the communication channel, which can be leveraged to disable OpenSSH 9.5's keystroke timing attack protections or downgrade the public key methods used for user authentication.
The Terrapin attack takes advantage of flaws in the SSH transport layer protocol along with updated cryptographic techniques and encryption modes that were first made available by OpenSSH read more Terrapin attacks can downgrade security of OpenSSH connections.
Get up to date on the latest cybersecurity news...

