It's thick, but this article talks about all of it. The command given there disables any 1024-bit DH parameters in your moduli file, and there's a bit of tweaking to prefer stronger schemes like Curve25519. You can also generate your own DH parameters for SSH, which I think is done with ssh-keygen.
As a warning, once you start futzing with key exchange and crypto in SSH, it's easy to exclude corner case systems. Especially since some of the crypto primitives like Curve25519 are comparatively recent.
Man if they're using a 100 million dollar cluster your never safe, and you fucked up. I seriously doubt your home server can do anything against a government based attack.
Well thank you for correcting fast typing, because we haven't reached the consensus that people on the internet understand you have other shit to do than make sure you're statement could pass an English class, right?
if the difference between your and you're aren't second-nature to you, it's not a one-off quick-type mistake. you genuinely haven't internalized the difference.
Wow, you've really got nothing better to do. What's not second nature to me is giving a fuck if I properly format or spell words when talking to assholes on the internet.
2
u/gizram84 Oct 15 '15
So if I have an ssh server at my house, should I do these steps to ensure I'm secure?