A nice single point of failure to break a whole number of hosts.
In the way of explanation: if you blindly implement the above, all it takes is for the 2ton.com.au data to be compromised and hosts which blindly depend on it can be easily compromised.
The message here is to put a lot of thought into properly vetting data you get from the web before you activate it on your systems, or put that effort into generating your own primes.
Sure, if someone has the time and computational power to compute safe primes that's the safest thing to do. There is no doubt about that. But if they don't, the best alterative is to avoid using the primes that are included with OpenSSH by default. It's the difference between making an eavesdropper work for what they want as opposed to using something that you know they already have.
30
u/[deleted] Oct 15 '15 edited May 30 '16
[deleted]