Re: On why debugging OpenSSH can be so hard



Please bear in mind that in the world of cryptography, the difference
between proper error messages and information disclosure
vulnerabilities is narrow, or only a nuance.

IMHO, you have it backwards. It is the improper error messages that can pose a security risk. If my OpenSSH program is either misconfigured or malfunctiong, and it may be exposing my systems to something nefarious, then how am I to efficiently debug it

That's why it fails at that point.

It meaning OpenSSH? So what do you mean by its failing? Because it doesn't let me debug efficiently, it fails to be a "nice" program? But that doesn't make sense given your later argument that suggests it shouldn't be a "nice" program because in this case,"nice" programs expose security risks. Unless, of course, you think the failure is OK, that the failure trumps the security risk you claim. Or you mean something else and I'm not getting it?

(I hope this response adds more to the discussion. :-))
--

Maurice Volaski, mvolaski@xxxxxxxxxxxx
Computing Support, Rose F. Kennedy Center
Albert Einstein College of Medicine of Yeshiva University



Relevant Pages

  • Re: Finding hardlinks
    ... error messages (coreutils 5 work fine). ... library fails to walk directories returning FTS_DC error. ... I didn't hardlink directories, I just patched stat, lstat and fstat to ...
    (Linux-Kernel)
  • Re: Finding hardlinks
    ... error messages (coreutils 5 work fine). ... library fails to walk directories returning FTS_DC error. ... collisions are archivers and other programs that recursively try to copy ...
    (Linux-Kernel)
  • Re: Backup Problems using Xcopy
    ... > Adding the /d switch prevents lots of unnecessary copying. ... > Now what about the error messages I mentioned in my ... If it fails then it fails for one of ... >>> Other backup tools will suffer from exactly the same problems. ...
    (microsoft.public.win2000.networking)
  • Re: RpcNsBindingLookupBegin() returns 1761:The entry is not found
    ... No warning error messages when it compiles. ... Is there any info on how to read the map file. ... Now it fails almost every time. ... The error code is 1761:'The ...
    (microsoft.public.vc.mfc)
  • Re: office 2002 cannot open or send files
    ... When you say, "Whenever they try to open the file, it fails", what error messages to these other people see, or what makes them ... When you say, "I can no longer open files that other people send me", what happens when you try? ... I've installed office 2003 and am having the same problem. ...
    (microsoft.public.word.application.errors)