I'm imagining it. Posting a patch to your website is surely better than rewriting ssh from scratch or licensing SSH.com SSH. (Sure, BSD requires less effort on your part, but the community gets less in return. That's not good for the continued existence of the project.)
Complete secrecy is the typical modus operandi of companies. You'd probably be paying extra for SSL telnet.
How many lawsuits figuring with the GPL have you seen?
I know of a handful and I've read and heard that the focus is not to sue but to educate the companies in compliance.
Huh? Who are all of these vendors with secret OpenSSH patches?