I see that the bug is marked as fixed, but it's still there in the latest Debian. Here's the timeline:
2014-04-26 Debian 7.5 released 2014-04-27 Bug marked as fixed 2014-05-05 Debian Live 7.5 released 2014-07-12 Debian 7.6 released 2014-07-23 Debian Live 7.6 released Surely the fix should have made it to Debian Live 7.6 by now? Especially since it's a security fix. The fix ( live.debian.net/gitweb/?p=live-config.git;a=commitdiff;h=e776761a3cff82 ) is supposed to modify the file /etc/ssh/sshd_config, but when running Debian Live 7.6 the file still contains the line "#PasswordAuthentication yes" and not "PasswordAuthentication no".