I-GitHub ivimbe okhiye be-SSH abakhiqizwe kusetshenziswa ilabhulali yokubhanqa izinkinobho

I-GitHub ivimbe okhiye be-SSH kubasebenzisi bamakhasimende e-Git asebenzisa umtapo wokhiye we-JavaScript ukwenza okhiye. Isibonelo, okhiye beklayenti le-Git GitKraken bavinjiwe. Ukuba sengozini kuholela ekukhiqizweni kokhiye ababikezelwe be-RSA ngenxa yephutha elehlisa kakhulu ikhwalithi ye-entropy lapho kukhiqizwa ukulandelana okungahleliwe kokhiye. Inkinga ilungiswe kukhiye ongukhiye 1.0.4 kanye nokukhishwa kwe-GitKraken 8.0.1.

Isizathu sokuba sengozini kwakuwukusetshenziswa kwekholi ye-β€œb.putByte(String.fromCharCode(next & 0xFF))” phakathi nenqubo yokwakha ukhiye, naphezu kweqiniso lokuthi indlela ye-fromCharCode ibizwe futhi ngendlela ye-putByte. Ukushaya usuka kuCharCode kabili (β€œString.fromCharCode(String.fromCharCode(olandelayo & 0xFF)”) kuholele ekutheni iningi le-entropy buffer ligcwaliswe ngoziro, i.e. ukhiye wakhiwe ngokusekelwe kudatha "engahleliwe", 97% ehlanganisa amaziro.

Source: opennet.ru

Engeza amazwana