OpenSSH 7.4 released
openssh.com
openssh.com
"OpenSSH is a 100% complete SSH protocol 2.0 implementation..."
This bug[0] calling out the fact that OpenSSH doesn't implement section 6.9 of RFC 4254 (which allows you to send signals to remote processes) has been open since 2008, complete with community submitted patches that implement that part of the protocol.
My recent pet Golang project[1] is a parallel remote command executor that uses OpenSSH, and I would really love the ability to better manage remote processes I execute via SSH.
There was some conversation about if it was appropriate to pass on certain signals, but that's about it. After Darren cleaned up some client UI issues that bugged him, he even suggested that we might see the patch in 5.4.
Does anyone know why there is no support for Curve448 being added? There is a draft RFC at https://tools.ietf.org/html/draft-ietf-curdle-ssh-curves-00 describing this, together with SHA-512.
Previous versions of OpenSSH have already supported the privately defined "curve25519-sha256@libssh.org" key exchange protocol.
I would similarly push for latest version of OpenSSL but that's harder to get right.
Refusing all RSA keys smaller than 1024 bits
The next release of OpenSSH will remove support for running sshd(8) with privilege separation disabled
That's not really the sort of decision application programmers should be making for sysadmins.
As a programmer you have the right (or maybe even obligation?) to write secure software and I would argue software that's hard or impossible to use insecurely. It should live up to the standards of the time of release, not the time of the release of the first version (in case of OpenSSH that would be more than seventeen years ago).
As a sysadmin you can always decide to stick with an old version if that is what the environment you operate in demands.
I think this proactive mentality of OpenSSH is an important part of their success and why it has such a good track record from a security point of view.
>As a programmer you have the right (or maybe even obligation?) to write secure software and I would argue software that's hard or impossible to use insecurely.
There is plenty of software where secure usage is not a concern and that's fine. Rather, it would be better to say that as programmers we have the job to ensure that our software is as fit for primary expected purpose as possible, and in particularly lacks any surprising gotchas. Sometimes within a given program's core purpose there are decisions that can only be properly made as part of deployment/usage and those are appropriately left to the sysadmin/user, but if something is directly contrary to core purpose then it's always worth questioning whether it needs to change.
In the case of OpenSSH in particular the core purpose is in fact secure links. We've all long had an insecure very fast virtual terminal system if we wanted it and it's called Telnet. There is no reason that any available built-in mode of OpenSSH crypto should ever be insecure. Asking to have obsolete methods generally considered to no longer be reliable to be "left up to the sysadmin" would be like asking it to have rot13 as a sysadmin option: completely contrary to the purpose and expected function of the program. Not just in security but in software in general any extra switches carry both developmental load (more code to go wrong), deployment load (more possibilities to make mistakes) and cognitive load, so they should always be considered to have inherent negative value and then asked to justify themselves, not considered to stick around forever by default.
These changes are very good for the vast majority of users as they removes two big opportunities to silently shoot yourself in the foot.
You'd think it would be, given where it comes from, who those people are and what it is. (tone: I'm just surprised)
Maybe submitter here on HN just put http. Would be better if it did the redirect automatically though.
But their server should also redirect normal users.
EDIT: ah no, different computers. On my personal computers I have it, not on my workplace computer. (and my point remains, they should redirect traffic)
This prevents all kinds of undesirable behaviour; like your ISP injecting JavaScript ads into the webpages you view.
Confidentiality is just a nice little side-benefit.
Who needs this? I have a ssh server on my ubuntu, do I need to update OpenSSH? Also, I have openssl installed (for some reason), is that the same thing?
OpenSSL is separate software, but it provides a cryptography library that OpenSSH (usually) uses. You will need it installed.