Follow @Openwall on Twitter for new release announcements and other news
[<prev] [<thread-prev] [day] [month] [year] [list]
Message-ID: <lhuqzq7ol6t.fsf@oldenburg.str.redhat.com>
Date: Thu, 26 Feb 2026 11:26:02 +0100
From: Florian Weimer <fweimer@...hat.com>
To: Marco Moock <mm@...fdsl.de>
Cc: oss-security@...ts.openwall.com
Subject: Re: Re: Telnetd Vulnerability Report

* Marco Moock:

> On 24.02.2026 05:05 kf503bla@...k.com kf503bla@...k.com wrote:
>
>> Who uses telnet anyway? It's deprecated. Everyone uses ssh for any
>> kind of remote access.
>
> In certain situations telnet is still being used, because it is
> supported on a wide range of systems, regardless of key (exchange)
> algorithms or hash algorithms.

Part of that is that the industry has moved to a threat model where it
is considered more secure to use an unauthenticated, unencrypted channel
rather than one that uses (for example) an HMAC based on SHA-1 for
integrity protection.

Thanks,
Florian

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.