Damus
meduzot · 6w
It's very similar to the [2008 Debian weak SSH key generation bug](https://www.cve.org/CVERecord?id=CVE-2008-0166). In both cases keys were created with insufficient entropy because the developers got error messages they didn't understand and ended up trying to "fix" these errors.