Rasp Pi Generates Weak SSH Keys
The Pi's popular Raspbian OS pursues secrecy without entropy.
The Debian-based Raspbian Linux system, which runs on the tiny and popular Raspberry Pi single-board computer systems, appears to have a problem generating potentially weak SSH keys. Because the Rasp Pi doesn't come with a monitor, many Pi owners use SSH as a primary means of communicating with the system. And although a majority of the consumer-end Pis are sitting behind firewalls on little home networks (uh, how safe are those little home firewalls?), Internet-connected Raspberry Pis have started to appear as web servers, weather stations, remote photography experiments, and security cameras.
The Register quotes a Rasp Pi message board note, “Many Linux distributions stockpile random seed data during installation, and then use that to prime the pool during first boot-up, but Raspbian doesn't work that way – it starts up ready to go straight from the SD card, and thus suffers from low entropy.”
On current Raspbian systems, hardware random number generation isn't enabled by default. The system uses the random data in the /dev/urandom pool to generate a host key, but the pool doesn't have enough entropy at the early stage where the keys are created.
The Raspbian developers say they will fix the issue in the next release. In the meantime, users who are concerned about SSH security should use the Pi's onboard hardware random number generator to see the /dev/urandom file and regenerate SSH host keys.
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
Container-Based Fedora Hummingbird Designed for Agent-First Builders
Fedora Hummingbird brings the same approach to the host OS as it does to containers to level up security.
-
Linux kernel Developers Considering a Kill Switch
With the rise of Linux vulnerabilities, the kernel developers are now considering adding a component that could help temporarily mitigate against them… in the form of a kill switch.
-
Fedora 44 Now Gaming Ready
The latest version of Fedora has been released with gaming support.
-
Manjaro 26.1 Preview Unveils New Features
The latest Manjaro 26.1 preview has been released with new desktop versions, a new kernel, and more.
-
Microsoft Issues Warning About Linux Vulnerability
The company behind Windows has released information about a flaw that affects millions of Linux systems.
-
Is AI Coming to Your Ubuntu Desktop?
According to the VP of Engineering at Canonical, AI could soon be added to the Ubuntu desktop distribution.
-
Framework Laptop 13 Pro Competes with the Best
Framework has released what might be considered the MacBook of Linux devices.
-
The Latest CachyOS Features Supercharged Kernel
The latest release of CachyOS brings with it an enhanced version of the latest Linux kernel.
-
Kernel 7.0 Is a Bit More Rusty
Linux kernel 7.0 has been released for general availability, with Rust finally getting its due.
-
France Says "Au Revoir" to Microsoft
In a move that should surprise no one, France announced plans to reduce its reliance on US technology, and Microsoft Windows is the first to get the boot.
