https://hamish.gate.ac.uk/posts/2015/01/14/has-nsa-cracked-ssh/

This is the relevant link:

I'd be cautious about concluding that, for example, "SSH is broken", on the basis of this fragmentary report. Claims of successful decryption of SSH sessions almost certainly don't mean that (a) public key protocols protecting key exchange are broken (GPG would be broken too), or (b) any of the suite of ciphers used by SSH is vulnerable. They could be talking about side-channels, like fooling people into ignoring warnings that server keys have changed, or about sessions initiated from compromised machines.

Reply via email to