OpenSSH password vulnerability on cellular connection? [answered]
In this Ars Technica article, a vulnerability of OpenSSH is described, which would enable a brute-force attack against a password login. I would like to know how vulnerable was my Jolla phone through this bug. Here is the context:
Long ago, I enabled the option "Remote connection - Allow signing in via SSH" on the phone, and left it on (I did some development on it). I already use a key pair to connect from my laptop, and I never connected the phone on a WLAN except mine, so I think I should be okay. But would it be theoretically possible to exploit this OpenSSH vulnerability through the data connection, which was very often enabled? Does the firewall in Sailfish even allow access to SSH through anything else except USB and WLAN? I'm thinking of random bots around the world, which might attempt to detect exposed SSH connections on the Internet (having SSH exposed isn't good practice at all).