sshd[28670]: fatal: Unable to negotiate with 40.112.150.31 port 47286: no matching cipher found. Their offer: aes256-ctr,aes192-ctr,aes128-ctr,aes256-cbc,aes192-cbc,aes128-cbc,3des-ctr,3des-cbc,twofish256-ctr,twofish192-ctr,twofish128-ctr,twofish256-cbc,twofish192-cbc,twofish128-cbc,twofish-cbc [preauth]
Hi andreaso, do you happen to have a list of encryption algs on your side? We don't support chacha20-poly1305 (yet) and afaik aes in gcm mode, but e.g. aes ctr are reliable so I find it strange these are not supported on your side.
Does it really matter that much what distro it ships with? As long as the laptop ships with any distro preinstalled that hardware tend to be properly supported by the Linux kernel, allowing you to feel safe about installing any other (up-to-date) distro.
I've got an older dell laptop that came with Ubuntu 12, bought in 2013. I assume everything worked back then, but I needed Windows for school.
Some months ago, wanting to switch, tried Ubuntu 14 and Debian 8. Couldn't get the graphics driver to work on either. Proprietary drivers, other than the ones in the Ubuntu repos, required a mismatch of older/newer library/kernel versions which I couldn't figure out how to get in Ubuntu. The open source driver claimed my hd7670m worked, but in reality I was getting the hd4000 performance out of it.
Everything else worked, a bit noisier though. Either way, I would definitely not feel safe when buying another Linux laptop, proper research is still required.
Tor also has extensive documentation about the threat model they protect against, and the limitations of that model.
If there were one thing I could change about security discussions, it's that you can't talk about security in the abstract -- only security relative to some threat or foe.
I think a lot of the conversation would change if we could get people to start talking about security that way.
Well, despite its imperfections, how does DNSSEC worsen security compared to regular DNS? Besides, it's not like the use of DNSSEC prevent you from continuing to also rely on additional measures; such as good old fashions CAs, or something better.
@dcc1: could you please email me at brian@<my username>.com? I work for Google Netops and would like to get some additional info from you so we can debug this.
Looks like it's the glue records that point to the actual server?
reply